Version: v0.25.0 (Latest)
Credential verification
Credential verification prepares the tenant verifier to request and evaluate presentations. It requires the Platform foundations group. It does not require the issuance group, although testing end to end needs a credential issued by Credential issuance or by another issuer you trust.
The journeys run in dependency order: the verifier itself, its behaviour settings, the DCQL queries and trust domains (independent of each other), the attachments and templates that bind them, and finally verification. Every journey opens with a read of the data it is about to change.
Journeys in this group
| Journey | What it covers | Complete first |
|---|---|---|
| 1. Set up the verifier | Read the tenant verifier client settings, set its public name, URLs and response decryption key, and give it a verifier design. | Onboard a tenant, Connect Azure KMS with BYOK and BYOC |
| 2. Adjust the verifier configuration | Read and adjust how the verifier signs request objects, how long sessions live, and how presentations reconcile to users. | Set up the verifier |
| 3. Author DCQL queries | Read the tenant DCQL queries, create and edit query configurations, derive queries from semantic-model channels, and manage their version history. | Set up the verifier |
| 4. Build trust domains and anchors | Read the tenant trust domains, create and activate a domain, add anchors, grant admission classes, and configure an mdoc VICAL on a provider anchor. | Onboard a tenant |
| 5. Bind trust and queries | Read the trust attachments and eligibility grants, cap which domains consumers may select, attach domains to the verifier and its DCQL queries, and create verification templates that pick a query. | Author DCQL queries, Build trust domains and anchors |
| 6. Verify credentials | Read the verification templates, create an OID4VP authorization request directly or from a template, then poll, read the result and cancel. | Bind trust and queries |
| 7. Choose status and trust policy | Read the status lists, trust domains and attachments that decide a verification, and use the decision matrix to choose status and trust per credential profile. | Verify credentials |
What EDK does and does not provide
- There is no EDK API to create verifier instances; the tenant verifier comes from onboarding.
- Per-verifier DCQL bindings are a VDX API. EDK binds trust to queries with
OID4VP_DCQL_QUERYattachments and binds queries to requests with verification templates.
The canonical EDK Enterprise collection
covers this group in 21 DCQL Queries, 23 Trust Domains and Trust Lists and 22 Verification.