This specification defines a protocol for requesting and presenting Credentials.¶
1. Introduction
1.1. Additional Authors
1.2. Errata revisions
1.3. Requirements Notation and Conventions
2. Terminology
3. Overview
3.1. Same Device Flow
3.2. Cross Device Flow
4. Scope
5. Authorization Request
5.1. New Parameters
5.2. Existing Parameters
5.3. Requesting Presentations without Holder Binding Proofs
5.4. Examples
5.5. Using scope Parameter to Request Presentations
scope
5.6. Response Type vp_token
vp_token
5.7. Passing Authorization Request Across Devices
5.8. aud of a Request Object
aud
5.9. Client Identifier Prefix and Verifier Metadata Management
5.9.1. Syntax
5.9.2. Fallback
5.9.3. Defined Client Identifier Prefixes
5.10. Request URI Method post
post
5.10.1. Request URI Response
5.10.2. Request URI Error Response
5.11. Verifier Info
5.11.1. Proof of Possession
6. Digital Credentials Query Language (DCQL)
6.1. Credential Query
6.1.1. Trusted Authorities Query
6.2. Credential Set Query
6.3. Claims Query
6.4. Selecting Claims and Credentials
6.4.1. Selecting Claims
6.4.2. Selecting Credentials
6.4.3. User Interface Considerations
7. Claims Path Pointer
7.1. Semantics for JSON-based credentials
7.1.1. Processing
7.2. Semantics for ISO mdoc-based credentials
7.2.1. Processing
7.3. Claims Path Pointer Example
7.4. DCQL Examples
8. Response
8.1. Response Parameters
8.1.1. Examples
8.2. Response Mode "direct_post"
8.3. Encrypted Responses
8.3.1. Response Mode "direct_post.jwt"
8.4. Transaction Data
8.5. Error Response
8.6. VP Token Validation
9. Wallet Invocation
10. Wallet Metadata (Authorization Server Metadata)
10.1. Additional Wallet Metadata Parameters
10.2. Obtaining Wallet's Metadata
11. Verifier Metadata (Client Metadata)
11.1. Additional Verifier Metadata Parameters
12. Verifier Attestation JWT
13. Implementation Considerations
13.1. Static Configuration Values of the Wallets
13.1.1. Profiles that Define Static Configuration Values
13.1.2. A Set of Static Configuration Values bound to openid4vp://
openid4vp://
13.2. Nested Presentations
13.3. Response Mode direct_post
direct_post
13.4. Pre-Final Specifications
14. Security Considerations
14.1. Preventing Replay of Verifiable Presentations
14.1.1. Presentations without Holder Binding Proofs
14.1.2. Verifiable Presentations
14.2. Session Fixation
14.3. Response Mode "direct_post"
14.3.1. Validation of the Response URI
14.3.2. Protection of the Response URI
14.3.3. Protection of the Authorization Response Data
14.4. End-User Authentication using Credentials
14.5. Encrypting an Unsigned Response
14.6. TLS Requirements
14.7. Incomplete or Incorrect Implementations of the Specifications and Conformance Testing
14.8. Always Use the Full Client Identifier
14.9. Security Checks on the Returned Credentials and Presentations
15. Privacy Considerations
15.1. User Consent
15.2. Privacy Notice
15.3. Purpose Legitimacy
15.4. Selective Disclosure
15.4.1. DCQL Value Matching
15.4.2. Strictly Necessary Claims
15.5. Verifier-to-Verifier Unlinkable Presentations
15.6. No Fingerprinting of the End-User
15.7. Information Security
15.8. Wallet to Verifier Communication
15.8.1. Establishing Trust in the Request URI
15.8.2. Authorization Requests with Request URI
15.9. Error Responses
15.9.1. wallet_unavailable Authorization Error Response
wallet_unavailable
15.9.2. Digital Credential API Error Responses
15.10. Establishing Trust in the Issuers
16. Normative References
17. Informative References
Appendix A. OpenID4VP over the Digital Credentials API
A.1. Protocol
A.2. Request
A.3. Signed and Unsigned Requests
A.3.1. Unsigned Request
A.3.2. Signed Request