Skip to main content
Version: v0.25.0 (Latest)

Bind trust and queries

Domains and queries do nothing until they are bound. Trust attachments bind an ordered list of domains to the verifier or a DCQL query for one usage, eligibility grants cap what may be attached, and verification templates bind a query and version to requests.

Complete first: Author DCQL queries, Build trust domains and anchors.

Steps and why they come in this order​

StepWhy here
1. Review attachments and eligibility grantsThe winning attachment decides every verification. Read what is attached at each level before writing a more specific one.
2. Set eligibility grantsThe grant is checked when a non-tenant attachment resolves. Widen it with the attachment change, not after a failed presentation.
3. Attach domains to the verifier and queriesThe attachment is what makes a domain answer for the verifier or one query. Write it once domains and grants are in place.
4. Create verification templatesA template pins the query, version and request defaults, so backends start verification without rebuilding the request.

The resolution cascade​

An attachment is keyed by (consumerKind, consumerId, usage) and looked up from the most specific consumer to the tenant. The first level with an attachment wins; levels are not merged.

Consumer kindLookup order
OID4VP_VERIFIERverifier, tenant
OID4VP_DCQL_QUERYquery, verifier, tenant
OID4VP_VERIFIER_DCQL_BINDINGbinding, query, verifier, tenant
OID4VP_REQUEST_TEMPLATEtemplate, binding, query, verifier, tenant

An attachment on a query replaces the verifier and tenant selection rather than extending it. An empty list under FAIL_CLOSED trusts nothing and stops the cascade; deleting the attachment reopens it. No attachment anywhere fails closed.

About DCQL-to-verifier binding. The per-verifier DCQL binding store (/api/dcql/v1/verifiers/{verifierId}/bindings) is defined in the VDX DCQL API, which is not projected for EDK. In EDK a query is bound to requests through a verification template (step 4), and trust is bound to the query through an OID4VP_DCQL_QUERY attachment (step 3).

Deeper reference​

Trust domains has captured attachment and eligibility requests. Credential Verifier: Trust domains explains the verifier settings surface.

Next journey​

Continue with Verify credentials.