Skip to main content

Wallet Unit Attestations for Issuers

You can require the wallet to provide valid attestations before issuing credentials. This includes attestations for:

  • App integrity — know that the wallet unit is a valid and uncompromised install from a trusted Wallet Provider ("WP"). This is a Wallet Instance Attestation ("WIA").

  • Key security — know that the wallet unit can generate keys for signing which are sufficiently secure for your issuance. This is a Key Attestation ("KA").

This page explains how to control Wallet Unit Attestation ("WUA") requirements for issuance.

Setting WUA requirements​

Use the walletAttestation block when creating credential schemas to set requirements for WUAs:

POST /api/credential-schema/v2

{
"walletAttestation": {
"requireInstanceAttestation": true,
"preferredInstanceAttestationLifetime": 2678400,
"keyStorageSecurityLevel": "HIGH",
"preferredKeyStorageAttestationLifetime": 2678400
},
...
}

Instance attestation​

  • Set requireInstanceAttestation to true to require a valid WIA from wallets during issuance. Wallets must present a signed WIA or issuance will fail.
    note

    To enforce that the WIA must be signed by a trusted WP, you must apply further constraints via Ecosystems.

  • Set preferredInstanceAttestationLifetime to a duration in seconds. This informs the WP your preferred status maintenance lifetime for WIAs, or how long the WP should guarantee to maintain the status list for issued WIAs. The value here is advertised in the issuer metadata as preferred_client_status_period.

The technical expiration of credentials you issue is constrained by two things:

  • Your format configuration; see Technical expiration
  • The status maintenance lifetime of the WIA presented by the wallet during issuance

When you require a WIA, or a WIA + KA, the technical expiration of the credential you issue will always match the lowest of the constraint values, never exceeding either your configuration or the status maintenance lifetime of the attestation.

Key attestation​

  • Set keyStorageSecurityLevel to a value from your configuration of keySecurityLevel to require a valid KA from wallets during issuance.
    note

    To enforce that the KA must be signed by a trusted WP, you must apply further constraints via Ecosystems.

  • Set preferredKeyStorageAttestationLifetime to a duration in seconds. This informs the WP your preferred status maintenance lifetime for KAs, or how long the WP should guarantee to maintain the status list for KAs. The value here is advertised in the issuer metadata as preferred_key_storage_status_period.

As above with instance attestations, the technical expiration of the credential you issue will always match the lowest of the constraint values.