Skip to main content
Version: v0.25.0 (Latest)

Credential Issuer: Credential Defaults

Catalog id: protocol.issuer.issuance-defaults
Scope: tenant and selected issuer instance

Open it​

NavigationProtocols > Credential Issuer > select an issuer > Credential Defaults
Deep link#tenant={tenant}&surface=issuer&instance={instance}&area=issuance-defaults

Issuer credential defaults screen example

Credential Defaults are inherited by credential configurations that do not override a field. The screen groups the settings into Cryptography, Keys and signing, Lifecycle and status, and Grants and offers. A per-credential value overrides the issuer default; an omitted value falls through to the platform default.

Important choices​

GroupExamples
CryptographyBinding methods, signing algorithms, and proof types.
Keys and signingDefault issuer signing key and public key/certificate association.
Lifecycle and statusValidity duration and status-list binding where the selected format supports it.
Grants and offersPre-authorized-code and authorization-code enablement, including transaction-code policy when the deployment exposes it.

Format-specific identity (vct for SD-JWT VC and doctype for mDoc) belongs to the credential configuration, not the issuer default. Keep mDoc status and DSC/IACA choices aligned with the wallet and verifier ecosystem; see Issue credentials.

REST operations​

GET   /api/platform/config/v1/tenants/{tenantId}/oid4vci/issuer/credential-defaults
PUT /api/platform/config/v1/tenants/{tenantId}/oid4vci/issuer/credential-defaults
PATCH /api/platform/config/v1/tenants/{tenantId}/oid4vci/issuer/credential-defaults

PUT replaces the issuer defaults; PATCH applies merge-patch semantics. The response includes effective values and source markers so an operator can distinguish an issuer override from a platform default. Use the generated Platform Config REST reference for the current schema.