Skip to main content

Wallet Unit Attestations

When creating credential schemas you can require the wallet to provide attestations related to:

  • App integrity — know that the wallet unit is a valid and uncompromised install from a trusted Wallet Provider ("WP"). This is a Wallet Instance Attestation ("WIA").

  • Key security — know that the wallet unit can generate keys for signing which are sufficiently secure for your issuance. This is a Key Attestation ("KA").

This page explains how to control Wallet Unit Attestation ("WUA") requirements for issuance.

How it works​

Setting WUA requirements​

Use the walletAttestation block when creating credential schemas to set requirements for WUAs:

POST /api/credential-schema/v2

{
"walletAttestation": {
"requireInstanceAttestation": true,
"preferredInstanceAttestationLifetime": 2678400,
"keyStorageSecurityLevel": "HIGH",
"preferredKeyStorageAttestationLifetime": 2678400
},
...
}

Instance attestation​

Set requireInstanceAttestation to true and

  • preferredInstanceAttestationLifetime

  • keyStorageSecurityLevel

  • preferredKeyStorageAttestationLifetime