Bind trust and queries
Domains and queries do nothing until they are bound. Trust attachments bind an ordered list of domains to the verifier or a DCQL query for one usage, eligibility grants cap what may be attached, and verification templates bind a query and version to requests.
Complete first: Author DCQL queries, Build trust domains and anchors.
Steps and why they come in this order
| Step | Why here |
|---|---|
| 1. Review attachments and eligibility grants | The winning attachment decides every verification. Read what is attached at each level before writing a more specific one. |
| 2. Set eligibility grants | The grant is checked when a non-tenant attachment resolves. Widen it with the attachment change, not after a failed presentation. |
| 3. Attach domains to the verifier and queries | The attachment is what makes a domain answer for the verifier or one query. Write it once domains and grants are in place. |
| 4. Create verification templates | A template pins the query, version and request defaults, so backends start verification without rebuilding the request. |
The resolution cascade
An attachment is keyed by (consumerKind, consumerId, usage) and looked up from the most specific
consumer to the tenant. The first level with an attachment wins; levels are not merged.
| Consumer kind | Lookup order |
|---|---|
OID4VP_VERIFIER | verifier, tenant |
OID4VP_DCQL_QUERY | query, verifier, tenant |
OID4VP_VERIFIER_DCQL_BINDING | binding, query, verifier, tenant |
OID4VP_REQUEST_TEMPLATE | template, binding, query, verifier, tenant |
An attachment on a query replaces the verifier and tenant selection rather than extending it. An
empty list under FAIL_CLOSED trusts nothing and stops the cascade; deleting the attachment reopens it.
No attachment anywhere fails closed.
About DCQL-to-verifier binding. The per-verifier DCQL binding store (/api/dcql/v1/verifiers/{verifierId}/bindings)
is defined in the VDX DCQL API, which is not projected for EDK. In EDK a query is bound to requests
through a verification template (step 4), and trust is bound to the query through an
OID4VP_DCQL_QUERY attachment (step 3).
Deeper reference
Trust domains has captured attachment and eligibility requests. Credential Verifier: Trust domains explains the verifier settings surface.
Next journey
Continue with Verify credentials.