Credential Issuer: Credential Defaults
Catalog id: protocol.issuer.issuance-defaults
Scope: tenant and selected issuer instance
Open it
| Navigation | Protocols > Credential Issuer > select an issuer > Credential Defaults |
| Deep link | #tenant={tenant}&surface=issuer&instance={instance}&area=issuance-defaults |

Credential Defaults are inherited by credential configurations that do not override a field. The screen groups the settings into Cryptography, Keys and signing, Lifecycle and status, and Grants and offers. A per-credential value overrides the issuer default; an omitted value falls through to the platform default.
Important choices
| Group | Examples |
|---|---|
| Cryptography | Binding methods, signing algorithms, and proof types. |
| Keys and signing | Default issuer signing key and public key/certificate association. |
| Lifecycle and status | Validity duration and status-list binding where the selected format supports it. |
| Grants and offers | Pre-authorized-code and authorization-code enablement, including transaction-code policy when the deployment exposes it. |
Format-specific identity (vct for SD-JWT VC and doctype for mDoc) belongs to the credential
configuration, not the issuer default. Keep mDoc status and DSC/IACA choices aligned with the
wallet and verifier ecosystem; see Issue credentials.
REST operations
GET /api/platform/config/v1/tenants/{tenantId}/oid4vci/issuer/credential-defaults
PUT /api/platform/config/v1/tenants/{tenantId}/oid4vci/issuer/credential-defaults
PATCH /api/platform/config/v1/tenants/{tenantId}/oid4vci/issuer/credential-defaults
PUT replaces the issuer defaults; PATCH applies merge-patch semantics. The response includes
effective values and source markers so an operator can distinguish an issuer override from a
platform default. Use the generated Platform Config REST reference
for the current schema.