Wallet Unit Attestations for Issuers
You can require the wallet to provide valid attestations before issuing credentials. This includes attestations for:
-
App integrity — know that the wallet unit is a valid and uncompromised install from a trusted Wallet Provider ("WP"). This is a Wallet Instance Attestation ("WIA").
-
Key security — know that the wallet unit can generate keys for signing which are sufficiently secure for your issuance. This is a Key Attestation ("KA").
This page explains how to control Wallet Unit Attestation ("WUA") requirements for issuance.
Setting WUA requirements
Use the walletAttestation block when creating credential schemas to set
requirements for WUAs:
POST /api/credential-schema/v2
{
"walletAttestation": {
"requireInstanceAttestation": true,
"preferredInstanceAttestationLifetime": 2678400,
"keyStorageSecurityLevel": "HIGH",
"preferredKeyStorageAttestationLifetime": 2678400
},
...
}
Instance attestation
- Set
requireInstanceAttestationtotrueto require a valid WIA from wallets during issuance. Wallets must present a signed WIA or issuance will fail.noteTo enforce that the WIA must be signed by a trusted WP, you must apply further constraints via Ecosystems.
- Set
preferredInstanceAttestationLifetimeto a duration in seconds. This informs the WP your preferred status maintenance lifetime for WIAs, or how long the WP should guarantee to maintain the status list for issued WIAs. The value here is advertised in the issuer metadata aspreferred_client_status_period.
The technical expiration of credentials you issue is constrained by two things:
- Your
formatconfiguration; see Technical expiration - The status maintenance lifetime of the WIA presented by the wallet during issuance
When you require a WIA, or a WIA + KA, the technical expiration of the credential you issue will always match the lowest of the constraint values, never exceeding either your configuration or the status maintenance lifetime of the attestation.
Key attestation
- Set
keyStorageSecurityLevelto a value from your configuration ofkeySecurityLevelto require a valid KA from wallets during issuance.noteTo enforce that the KA must be signed by a trusted WP, you must apply further constraints via Ecosystems.
- Set
preferredKeyStorageAttestationLifetimeto a duration in seconds. This informs the WP your preferred status maintenance lifetime for KAs, or how long the WP should guarantee to maintain the status list for KAs. The value here is advertised in the issuer metadata aspreferred_key_storage_status_period.
As above with instance attestations, the technical expiration of the credential you issue will always match the lowest of the constraint values.