Implement OID4VCI (OpenID for Verifiable Credential Issuance 1.0) credential endpoint for a wallet

domain: openid.net · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Publish the issuer metadata at /.well-known/openid-credential-issuer including credential_issuer, credential_endpoint, credentials_supported array with format, types, and cryptographic_binding_methods_supported
  2. Implement the authorization code flow with PAR: the wallet sends the credential request parameters via PAR (RFC 9126), receives a request_uri, then redirects the user to the authorization endpoint
  3. Issue a credential offer (credential_offer or credential_offer_uri) for pre-authorized code flow when appropriate; include the pre-authorized_code and tx_code if PIN is required
  4. At the credential endpoint (POST /credentials), validate the Bearer access token, check the credential_identifier or format+types requested, verify the proof of possession JWT (proof.jwt) signed by the wallet's key
  5. Generate the credential (W3C VC, SD-JWT VC, or mDL as requested), sign it, and return {credential, c_nonce, c_nonce_expires_in} in the response
  6. Support the deferred issuance flow: return {acceptance_token} if the credential is not immediately available; implement the deferred endpoint (POST /deferred_credential) for polling

Known gotchas

Related routes

Implement OID4VCI (OpenID for Verifiable Credential Issuance) credential endpoint for a wallet
openid.net · 5 steps · unrated
Implement OID4VP (OpenID for Verifiable Presentations) verifier endpoint to request and verify W3C VC or mdoc credentials
openid.net · 5 steps · unrated
Implement an OpenID4VP relying party integration to request and verify attributes from an EU Digital Identity (EUDI) Wallet under the eIDAS 2.0 Architecture and Reference Framework
eudi-wallet.eu · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans