Skip to main content

Presentation Configuration

Fields of a presentation configuration, as accepted by POST /api/verifier/config and in config/<tenant>/presentation/<id>.json. PATCH /api/verifier/config/{id} accepts the same fields, all optional. For the task-oriented guide see Configure Verification.

Fields​

The table is generated at build time from the Zod schema the backend validates with. The schema is strict: unknown fields are rejected. dcql_query.credentials[] has one shape per format (mso_mdoc and dc+sd-jwt).

FieldRequiredType / allowed valuesDescription
idyesstringPresentation configuration identifier.
descriptionnostring or nullOptional presentation configuration description.
lifeTimenointeger (minimum 1)Presentation request lifetime in seconds.
skewSecondsnointeger (minimum 0)Clock skew tolerance in seconds.
statusCheckModenostring: strict | best_effort | disabledRevocation/status check mode.
dcql_queryyesobjectDCQL query defining requested credentials and claims.
dcql_query.credentialsyesarray of one of 2 shapesCredential queries requested by the verifier.
dcql_query.credentials[].idyesstringOnly in shape 1 of 2. Credential query identifier.
dcql_query.credentials[].multiplenobooleanOnly in shape 1 of 2. Allow multiple matching credentials.
dcql_query.credentials[].claim_setsnoarray of array of stringOnly in shape 1 of 2. Optional claim set constraints.
dcql_query.credentials[].trusted_authoritiesnoarray of one of 2 shapesOnly in shape 1 of 2. Optional trusted authority constraints.
dcql_query.credentials[].trusted_authorities[].typeyesstring: etsi_tlOnly in shape 1 of 2. Trusted authority type discriminator for ETSI trust lists.
dcql_query.credentials[].trusted_authorities[].valuesyesarray of objectOnly in shape 1 of 2. Trust list references for ETSI TL verification.
dcql_query.credentials[].trusted_authorities[].values[].trustListIdnostringOnly in shape 1 of 2. Optional trust list id reference.
dcql_query.credentials[].trusted_authorities[].values[].urlnostringOnly in shape 1 of 2. Optional trust list URL reference.
dcql_query.credentials[].trusted_authorities[].values[].verifierKeynoobjectOnly in shape 1 of 2. Optional verifier key material.
dcql_query.credentials[].trusted_authorities[].values[].verifierX509DernostringOnly in shape 1 of 2. Optional verifier certificate in DER/base64 form.
dcql_query.credentials[].trusted_authorities[].typeyesstring: openid_federationOnly in shape 2 of 2. Trusted authority type discriminator for OpenID Federation.
dcql_query.credentials[].trusted_authorities[].valuesyesarray of stringOnly in shape 2 of 2. OpenID Federation authority identifiers.
dcql_query.credentials[].formatyesstring: mso_mdocOnly in shape 1 of 2. Credential format discriminator.
dcql_query.credentials[].metayesobjectOnly in shape 1 of 2.
dcql_query.credentials[].meta.doctype_valueyesstringOnly in shape 1 of 2. Expected mDoc doctype value.
dcql_query.credentials[].claimsnoarray of objectOnly in shape 1 of 2. Optional mDoc claim-level constraints.
dcql_query.credentials[].claims[].idnostringOnly in shape 1 of 2. Optional claim query id.
dcql_query.credentials[].claims[].pathyesarray of string | numberOnly in shape 1 of 2. Path to the claim value in presented credentials.
dcql_query.credentials[].claims[].valuesnoarray of one of 3 shapesOnly in shape 1 of 2. Optional allowed values for the claim. A disclosed value must equal one of them in type and value.
dcql_query.credentials[].claims[].intent_to_retainnobooleanOnly in shape 1 of 2. Whether relying party intends to retain the claim.
dcql_query.credentials[].idyesstringOnly in shape 2 of 2. Credential query identifier.
dcql_query.credentials[].multiplenobooleanOnly in shape 2 of 2. Allow multiple matching credentials.
dcql_query.credentials[].claim_setsnoarray of array of stringOnly in shape 2 of 2. Optional claim set constraints.
dcql_query.credentials[].trusted_authoritiesnoarray of one of 2 shapesOnly in shape 2 of 2. Optional trusted authority constraints.
dcql_query.credentials[].trusted_authorities[].typeyesstring: etsi_tlOnly in shape 1 of 2. Trusted authority type discriminator for ETSI trust lists.
dcql_query.credentials[].trusted_authorities[].valuesyesarray of objectOnly in shape 1 of 2. Trust list references for ETSI TL verification.
dcql_query.credentials[].trusted_authorities[].values[].trustListIdnostringOnly in shape 1 of 2. Optional trust list id reference.
dcql_query.credentials[].trusted_authorities[].values[].urlnostringOnly in shape 1 of 2. Optional trust list URL reference.
dcql_query.credentials[].trusted_authorities[].values[].verifierKeynoobjectOnly in shape 1 of 2. Optional verifier key material.
dcql_query.credentials[].trusted_authorities[].values[].verifierX509DernostringOnly in shape 1 of 2. Optional verifier certificate in DER/base64 form.
dcql_query.credentials[].trusted_authorities[].typeyesstring: openid_federationOnly in shape 2 of 2. Trusted authority type discriminator for OpenID Federation.
dcql_query.credentials[].trusted_authorities[].valuesyesarray of stringOnly in shape 2 of 2. OpenID Federation authority identifiers.
dcql_query.credentials[].formatyesstring: dc+sd-jwtOnly in shape 2 of 2. Credential format discriminator.
dcql_query.credentials[].metayesobjectOnly in shape 2 of 2.
dcql_query.credentials[].meta.vct_valuesyesarray of stringOnly in shape 2 of 2. Accepted VCT values.
dcql_query.credentials[].claimsnoarray of objectOnly in shape 2 of 2. Optional claim-level constraints.
dcql_query.credentials[].claims[].idnostringOnly in shape 2 of 2. Optional claim query id.
dcql_query.credentials[].claims[].pathyesarray of string | numberOnly in shape 2 of 2. Path to the claim value in presented credentials.
dcql_query.credentials[].claims[].valuesnoarray of one of 3 shapesOnly in shape 2 of 2. Optional allowed values for the claim. A disclosed value must equal one of them in type and value.
dcql_query.credential_setsnoarray of objectOptional higher-level credential set requirements.
dcql_query.credential_sets[].optionsyesarray of array of stringAlternative credential query id combinations.
dcql_query.credential_sets[].requirednobooleanWhether this credential set is mandatory.
transaction_datanoarray of object or nullOptional transaction data descriptors.
transaction_data[].typeyesstringTransaction data type identifier.
transaction_data[].credential_idsyesarray of stringCredential query ids this transaction data applies to.
transaction_data[].payloadnoanyTransaction details. Required for TS12 SCA transaction data.
registration_certnoobject or nullOptional registration certificate request settings.
registration_cert.idnostring
registration_cert.bodynoobject
registration_cert.body.privacy_policynostring
registration_cert.body.support_urinostring
registration_cert.body.intermediarynostring
registration_cert.body.purposenoarray of object
registration_cert.body.purpose[].langyesstring
registration_cert.body.purpose[].contentyesstring
registration_cert.body.credentialsnoarray of object
registration_cert.body.provides_attestationsnoarray of string
registration_cert.jwtnostring
registrationCertImportJwtnostring or nullOptional imported registration certificate JWT.
registrationCertImportIdnostring or nullOptional registrar-side registration certificate id.
registrationCertBodyPrivacyPolicynostring or nullOptional registration certificate privacy policy URI.
registrationCertBodySupportUrinostring or nullOptional registration certificate support URI.
registrationCertBodyIntermediarynostring or nullOptional registration certificate intermediary.
registrationCertBodyPurposenoarray of object or nullOptional registration certificate purpose entries.
registrationCertBodyPurpose[].langnostring
registrationCertBodyPurpose[].contentnostring
webhookEndpointIdnostring or nullOptional webhook endpoint id for presentation callbacks.
attachednoarray of object or nullOptional attachments included with presentation requests.
attached[].formatyesstringAttachment format identifier.
attached[].datayesanyAttachment payload.
attached[].credential_idsnoarray of stringOptional credential query ids bound to this attachment.
redirectUrinostring or nullOptional redirect URI after presentation completion.
accessKeyChainIdnostring or nullOptional key chain id for access token/auth operations.
readerAuthnoboolean or nullWhether reader authentication is required for mDoc requests.

Defaults and behavior​

FieldDefault and behavior
idUsed as requestId in presentation requests.
descriptionInternal only; not shown to the wallet user.
lifeTime300. Seconds until a request created from this configuration expires (expiresAt of the session).
skewSeconds60. Clock skew tolerance for credential time checks; a request can override it.
statusCheckModestrict: status lists are checked and verification fails if a status list cannot be fetched or validated. best_effort: verification continues without the status result when the status list is unavailable. disabled: no status check. Applies to SD-JWT VC and mDOC, including ISO 18013-7.
dcql_querySee DCQL. <TENANT_URL> anywhere in the query is replaced with <PUBLIC_URL>/issuers/<tenant>.
transaction_dataSent with every request unless the request sets its own transaction_data. Ignored for ISO 18013-7. See Transaction Data.
registration_certStrategies jwt, id, body. Only attached when the tenant has a registrar configuration. See Registration Certificates.
registrationCert*Flat form fields used by the Web Client. They are converted into registration_cert (only when registration_cert is not sent) and are not stored.
webhookEndpointIdID of a webhook endpoint that receives results. A request can override it with an inline webhook.
attachedStored with the configuration; currently not sent to the wallet.
redirectUriSame-device redirect target. {sessionId} is replaced with the session ID. A request can override it, except for ISO 18013-7. See Receive Results.
accessKeyChainIdAccess key chain that signs the request, determines the client_id and signs readerAuth. Without it, EUDIPLO uses an access key chain of the tenant; set it when the tenant has several.
readerAuthfalse. ISO 18013-7 only: sign the DeviceRequest with the access key chain. Requires the db KMS provider for that key.

Validation rules​

Rules that the table cannot show:

  • dcql_query.credentials needs at least one entry; credential query IDs contain only letters, digits, _ and -, and are unique.
  • meta is required: vct_values (at least one) for dc+sd-jwt, doctype_value for mso_mdoc.
  • Every ID in claim_sets must reference the id of a claim in the same credential query; claim IDs are unique.
  • transaction_data entries whose type starts with urn:eudi:sca: must be a supported TS12 type with a valid payload.

Server-managed fields​

Responses also contain createdAt, updatedAt and registrationCertCache (the registration certificate EUDIPLO resolved, with fingerprints and expiry). They are read-only and not part of the schema, so the API rejects them in a request body. EUDIPLO clears the cache when registration_cert or dcql_query changes and refreshes it in the background. To force a new certificate, call POST /api/verifier/config/{id}/registration-cert/reissue.