Skip to main content
Version: v0.25.0 (Latest)

Issue credentials

Issuance starts with a backend credential offer and ends when a separate wallet exchanges its grant and requests the credential. This journey covers the backend side: offers, reusable issuance templates, and the attribute pipeline session that supplies claim values.

Complete first: Configure credential configurations.

Steps and why they come in this order​

StepWhy here
1. Review issuance templatesA template may already hold the grant, design version and lifecycle settings you need. Check before building offers by hand.
2. Create and track an offerThe offer creates the issuance session the wallet redeems. Its correlation id is the handle for everything after.
3. Define issuance templatesOnce one offer works, capture its stable parts in a template so backends request offers without rebuilding them.
4. Supply attributes through a pipeline sessionWhen claim values come from backends at issuance time, the pipeline session collects and approves them before the credential is signed.

The response-derived chain​

issuer metadata > credential_offer > pre-authorized_code or authorization_code
> wallet access token > (nonce endpoint > c_nonce, when advertised)
> credential request with proof
> credential + status URI and index

The tenant token creates offers and templates. The wallet token belongs to one issuance session and is used only for token and credential protocol calls, which are standard OID4VCI endpoints advertised in issuer metadata rather than operations in these specs. An offer is an entry point, not issuance.

Deeper reference​

Issue credentials walks the full pre-authorized and authorization-code flows with captures from 15 Issue SD-JWT VC and mdoc. Attribute Pipeline explains connector stages and callbacks.

Next journey​

Continue with Prove the credential status profiles.