Version: v0.25.0 (Latest)
Configure request-object signing
Step 2 of 4 in Adjust the verifier configuration.
Loading example...
| Field | Meaning |
|---|---|
enabled | Sign authorization request objects |
mode | did:jwk, did:web, did:webvh, did:key, x509_san_dns or x509_hash |
kmsResourceHandle, kmsKeyAlias | Key that signs request objects |
didWebDomain | Domain used when mode is did:web |
sanDnsName | DNS subject alternative name for certificate-bound modes |
verificationMethodId, verificationMethodFragment | Verification method advertised for the signature |
includeIss, audience, expirationSeconds | Claims and lifetime of the signed request object |
For the X.509 modes, the certificate chain registered in the KMS journey must carry the SAN or hash the mode declares. A mismatch fails at the wallet, not at this call.
Next
Continue with step 3, Set the session lifetime.