Issue credentials
Issuance starts with a backend credential offer and ends when a separate wallet exchanges its grant and requests the credential. This journey covers the backend side: offers, reusable issuance templates, and the attribute pipeline session that supplies claim values.
Complete first: Configure credential configurations.
Steps and why they come in this order
| Step | Why here |
|---|---|
| 1. Review issuance templates | A template may already hold the grant, design version and lifecycle settings you need. Check before building offers by hand. |
| 2. Create and track an offer | The offer creates the issuance session the wallet redeems. Its correlation id is the handle for everything after. |
| 3. Define issuance templates | Once one offer works, capture its stable parts in a template so backends request offers without rebuilding them. |
| 4. Supply attributes through a pipeline session | When claim values come from backends at issuance time, the pipeline session collects and approves them before the credential is signed. |
The response-derived chain
issuer metadata > credential_offer > pre-authorized_code or authorization_code
> wallet access token > (nonce endpoint > c_nonce, when advertised)
> credential request with proof
> credential + status URI and index
The tenant token creates offers and templates. The wallet token belongs to one issuance session and is used only for token and credential protocol calls, which are standard OID4VCI endpoints advertised in issuer metadata rather than operations in these specs. An offer is an entry point, not issuance.
Deeper reference
Issue credentials walks the full pre-authorized and
authorization-code flows with captures from 15 Issue SD-JWT VC and mdoc.
Attribute Pipeline explains connector stages and callbacks.
Next journey
Continue with Prove the credential status profiles.