Set security, issuance behaviour and credential defaults
Step 4 of 6 in Set up the credential issuer.
Security controls credential request and response encryption: the mode, the supported
alg, enc and zip values, whether encryption is required, and the KMS key used to decrypt
encrypted requests.
Issuance controls runtime behaviour: batchCredentialIssuanceMaxSize, issuanceClockSkewInSeconds,
the walletInitiatedSubjectAttributes registry used for wallet-initiated issuance, and
missingRequiredClaims (reject returns an error at the credential endpoint, defer holds the
request until the claims arrive).
Credential defaults are the issuer layer beneath per-configuration settings: cryptographic
binding methods, signing algorithms, proof types, the default signing key, validity, status binding
where the format supports it, and grant policy. PUT replaces the defaults (omitted fields return to
the platform default); PATCH merges.
Format identity (format, scope, vct, docType) has no issuer default; it belongs to each
credential configuration. Inheritance is live: changing a default immediately changes every
configuration that does not override it.
Next
Continue with step 5, Bind the authorization server.