Skip to main content
Version: v0.25.0 (Latest)

Check what the issuer publishes

Step 6 of 6 in Set up the credential issuer.

There is no OpenAPI operation that returns the published /.well-known/openid-credential-issuer document. It is a public protocol endpoint, read anonymously by wallets, and it is generated from the stored settings, the credential configurations and the designs. To check it:

  1. List the calling tenant's issuer instances and read the issuer's credentialIssuer and public endpoints. These tenant-facing reads use the tenant application token.
Loading example...
Loading example...
  1. Fetch the public URL with no Authorization header, for example GET https://acme.example.com/.well-known/openid-credential-issuer.
  2. Compare credential_issuer and display with the stored metadata settings:
Loading example...
  1. Once credential configurations exist, check that every configuration you expect appears in credential_configurations_supported with the format, identifier and proof types you set.

A configuration missing from the published document usually means its design, status list or signing selection does not validate, not that the metadata endpoint is broken. The Admin Console Test area (area=test) shows the same published document for an operator.

Next​

This completes the journey. Continue with Design the issuer.