Skip to main content
Version: v0.25.0 (Latest)

Configure request-object signing

Step 2 of 4 in Adjust the verifier configuration.

Loading example...
FieldMeaning
enabledSign authorization request objects
modedid:jwk, did:web, did:webvh, did:key, x509_san_dns or x509_hash
kmsResourceHandle, kmsKeyAliasKey that signs request objects
didWebDomainDomain used when mode is did:web
sanDnsNameDNS subject alternative name for certificate-bound modes
verificationMethodId, verificationMethodFragmentVerification method advertised for the signature
includeIss, audience, expirationSecondsClaims and lifetime of the signed request object

For the X.509 modes, the certificate chain registered in the KMS journey must carry the SAN or hash the mode declares. A mismatch fails at the wallet, not at this call.

Next​

Continue with step 3, Set the session lifetime.