Authorization
Handles the creation of an authorization request. Creates a new authorization request with the provided presentation definition.
Request body for creating an authorization request
Redirect URI to which the response will be sent
http://example.comValidity of the authorization request in seconds
600Created
Response for a successful authorization request creation
Request URI that can be used to create a QR code
http://127.0.0.1:9004/api/v1/verifier/authorization-request/a0b2e682-d92f-4767-a83a-d60d196da792URL of the QR code that can be scanned by wallets
http://127.0.0.1:9004/api/v1/verifier/qr-code/a0b2e682-d92f-4767-a83a-d60d196da792Random string to prevent CSRF attacks
abcdef12345678901234567890abcdefRandom string to ensure request uniqueness
1234567890abcdef1234567890abcdefValidity of the authorization request in seconds
600Bad Request
POST /api/v1/verifier/authorization-requests HTTP/1.1
x-client-secret: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 208
{
"redirect_uri": "http://example.com",
"presentation_definition": {
"input_descriptors": [
{
"constraints": {
"fields": [
"[Circular Reference]"
],
"limit_disclosure": "required"
},
"id": "text"
}
],
"id": "text"
},
"validity": 600
}{
"request_uri": "http://127.0.0.1:9004/api/v1/verifier/authorization-request/a0b2e682-d92f-4767-a83a-d60d196da792",
"qr_code_url": "http://127.0.0.1:9004/api/v1/verifier/qr-code/a0b2e682-d92f-4767-a83a-d60d196da792",
"state": "abcdef12345678901234567890abcdef",
"nonce": "1234567890abcdef1234567890abcdef",
"validity": 600
}Retrieves an authorization request by ID. Returns the details of the specified authorization request.
Found
Entity representing an authorization request in the verifier service.
An authorization request is created when a client requests verification of credentials. It contains all the necessary information to process a verifiable presentation, including the presentation definition that specifies what credentials are required, and state/nonce values for security purposes.
Unique identifier for the authorization request. Automatically generated as a UUID.
State parameter used for SIOP (Self-Issued OpenID Provider) flow. Helps prevent cross-site request forgery attacks by maintaining state between requests. Must be unique when combined with nonce.
Nonce (number used once) parameter for the authorization request. Provides replay protection and ensures the response is generated for this specific request. Must be unique when combined with state.
URI where the client should be redirected after the verification process. The verification result will be sent to this URI.
Timestamp (in milliseconds) until which this authorization request is valid. After this time, the request will be considered expired and cannot be used.
URI where the wallet should submit the verifiable presentation. This is the endpoint that will receive and process the VP from the wallet.
Flag indicating whether this authorization request has been used. Prevents the same authorization request from being used multiple times. Set to true after a successful verification process.
falseBad Request
GET /api/v1/verifier/authorization-requests/{id} HTTP/1.1
Accept: */*
{
"id": "text",
"state": "text",
"nonce": "text",
"redirect_uri": "text",
"validity": 1,
"response_uri": "text",
"presentation_definition": {
"input_descriptors": [
{
"constraints": {
"fields": [
"[Circular Reference]"
],
"limit_disclosure": "required"
},
"id": "text"
}
],
"id": "text"
},
"used": false
}Handles the deletion of an authorization request by ID. Removes the specified authorization request from the system.
No Content
No content
Bad Request
DELETE /api/v1/verifier/authorization-requests/{id} HTTP/1.1
x-client-secret: YOUR_API_KEY
Accept: */*
No content
Handler for the 'submit-vp' endpoint. Processes a submitted verifiable presentation, validates it against the presentation definition, and sends the verification result to the redirect URI.
Request body for submitting a verifiable presentation
Random string to prevent CSRF attacks
abcdef12345678901234567890abcdefRandom string to ensure request uniqueness
1234567890abcdef1234567890abcdefSuccess
Bad Request
POST /api/v1/verifier/verifiable-presentations HTTP/1.1
Content-Type: application/json
Accept: */*
Content-Length: 1265
{
"vp_token": {
"proof": {
"challange": "text",
"nonce": "text",
"jws": "text",
"proofValue": "text",
"proofPurpose": "assertionMethod",
"verificationMethod": "text",
"created": "text",
"type": "EcdsaSecp256k1Signature2019"
},
"holder": "text",
"id": "text",
"verifiableCredential": [
{
"evidence": {},
"credentialStatus": [
{
"id": "text",
"type": "BitstringStatusListEntry",
"statusPurpose": "refresh",
"statusListIndex": 1,
"statusListCredential": "text",
"statusSize": 1,
"statusMessage": [
{
"message": "text",
"status": "text",
"ANY_ADDITIONAL_PROPERTY": "anything"
}
]
}
],
"credentialSchema": {
"type": "JsonSchemaValidator2018",
"id": "text"
},
"expirationDate": "text",
"proof": {
"challange": "text",
"nonce": "text",
"jws": "text",
"proofValue": "text",
"proofPurpose": "assertionMethod",
"verificationMethod": "text",
"created": "text",
"type": "EcdsaSecp256k1Signature2019"
},
"credentialSubject": {
"ANY_ADDITIONAL_PROPERTY": "anything"
},
"issuanceDate": "text",
"issuer": {
"name": "text",
"id": "text"
},
"id": "text",
"type": [
"text"
],
"@context": [
"text"
]
}
],
"type": "text",
"@context": [
"text"
]
},
"presentation_submission": {
"descriptor_map": [
{
"path_nested": {
"format": "text",
"path": "text"
},
"format": "text",
"path": "text",
"id": "text"
}
],
"definition_id": "text",
"id": "text"
},
"state": "abcdef12345678901234567890abcdef",
"nonce": "1234567890abcdef1234567890abcdef"
}{
"message": "text"
}Last updated