Wallet Unit Attestations
When creating credential schemas you can require the wallet to provide attestations related to:
-
App integrity — know that the wallet unit is a valid and uncompromised install from a trusted Wallet Provider ("WP"). This is a Wallet Instance Attestation ("WIA").
-
Key security — know that the wallet unit can generate keys for signing which are sufficiently secure for your issuance. This is a Key Attestation ("KA").
This page explains how to control Wallet Unit Attestation ("WUA") requirements for issuance.
How it works
Setting WUA requirements
Use the walletAttestation block when creating credential schemas to set
requirements for WUAs:
POST /api/credential-schema/v2
{
"walletAttestation": {
"requireInstanceAttestation": true,
"preferredInstanceAttestationLifetime": 2678400,
"keyStorageSecurityLevel": "HIGH",
"preferredKeyStorageAttestationLifetime": 2678400
},
...
}
Instance attestation
Set requireInstanceAttestation to true and
-
preferredInstanceAttestationLifetime -
keyStorageSecurityLevel -
preferredKeyStorageAttestationLifetime