SD-JWT VC with JWT Token Status
Step 2 of 5 in Prove the credential status profiles.
Profile. An SD-JWT VC design bound to dc+sd-jwt and a vct, and an IETF JWT Token Status List
published as application/statuslist+jwt.
Setup. Create the design and the standalone JWT status list as separate resources. Sign the list with the same key and DID assertion method (or certificate) the issuer signs credentials with, so verifiers see one signer. Bind the returned list id in the credential configuration.
Offer. Create the backend offer with the advertised SD-JWT configuration (EuPid in the example):
Checks. The wallet decodes the credential as SD-JWT VC and checks issuer, vct, claims, validity
and the embedded status URI and index. A successful credential response is not a presentation.
Status transition. Change the response-derived index, then fetch the refreshed JWT anonymously. A verifier validates the JWT and its TTL, reads the index and rejects a revoked or unavailable entry. A stale cache, wrong URI or index, invalid signature or malformed token is fail closed.
- Overview
- Request
- Response
Fetch hosted status list token
Endpoint: GET /public/statuslists/eupid-revocation
Captured response: 200 OK
This captured endpoint is shown from the E2E run; it is not mapped to one of the generated EDK REST API reference pages.
Connect an environment to rewrite this call to real service bases and run it.
Full walkthrough, console and REST tabs, and the wallet-request illustration: section "SD-JWT VC + JWT Token Status" of the profile walkthroughs.
Next
Continue with step 3, ISO mdoc with CWT Token Status.