Skip to main content
Version: v0.25.0 (Latest)

Credential verification

Credential verification prepares the tenant verifier to request and evaluate presentations. It requires the Platform foundations group. It does not require the issuance group, although testing end to end needs a credential issued by Credential issuance or by another issuer you trust.

The journeys run in dependency order: the verifier itself, its behaviour settings, the DCQL queries and trust domains (independent of each other), the attachments and templates that bind them, and finally verification. Every journey opens with a read of the data it is about to change.

Journeys in this group​

JourneyWhat it coversComplete first
1. Set up the verifierRead the tenant verifier client settings, set its public name, URLs and response decryption key, and give it a verifier design.Onboard a tenant, Connect Azure KMS with BYOK and BYOC
2. Adjust the verifier configurationRead and adjust how the verifier signs request objects, how long sessions live, and how presentations reconcile to users.Set up the verifier
3. Author DCQL queriesRead the tenant DCQL queries, create and edit query configurations, derive queries from semantic-model channels, and manage their version history.Set up the verifier
4. Build trust domains and anchorsRead the tenant trust domains, create and activate a domain, add anchors, grant admission classes, and configure an mdoc VICAL on a provider anchor.Onboard a tenant
5. Bind trust and queriesRead the trust attachments and eligibility grants, cap which domains consumers may select, attach domains to the verifier and its DCQL queries, and create verification templates that pick a query.Author DCQL queries, Build trust domains and anchors
6. Verify credentialsRead the verification templates, create an OID4VP authorization request directly or from a template, then poll, read the result and cancel.Bind trust and queries
7. Choose status and trust policyRead the status lists, trust domains and attachments that decide a verification, and use the decision matrix to choose status and trust per credential profile.Verify credentials

What EDK does and does not provide​

  • There is no EDK API to create verifier instances; the tenant verifier comes from onboarding.
  • Per-verifier DCQL bindings are a VDX API. EDK binds trust to queries with OID4VP_DCQL_QUERY attachments and binds queries to requests with verification templates.

The canonical EDK Enterprise collection covers this group in 21 DCQL Queries, 23 Trust Domains and Trust Lists and 22 Verification.