Create a wallet attestation signer
Roles
Analytics Events
/v1/holder/certificates/wallet-attestation-signersCreates a wallet attestation signer for an unmanaged root CA and returns its Certificate Signing Request (CSR).
This endpoint is only available for unmanaged roots — managed root signers are auto-provisioned on demand during the first wallet attestation request and never need to be created explicitly.
The returned signer is created with active: false; use the CSR to obtain a signed certificate externally and upload it via PUT /v1/holder/certificates/wallet-attestation-signers/{certificateId} to activate the signer.
A maximum of five wallet attestation signers can be created per root.
Analytic events
- CREDENTIAL_HOLDER_WALLET_ATTESTATION_SIGNER_CERTIFICATE_CREATE_START
- CREDENTIAL_HOLDER_WALLET_ATTESTATION_SIGNER_CERTIFICATE_CREATE_SUCCESS
- CREDENTIAL_HOLDER_WALLET_ATTESTATION_SIGNER_CERTIFICATE_CREATE_FAIL
Authorization
bearerAuth In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/holder/certificates/wallet-attestation-signers" \ -H "Content-Type: application/json" \ -d '{ "caId": "24c00dcc-a2d5-4635-ba3f-14dcbc0a8ea3" }'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "caId": "24c00dcc-a2d5-4635-ba3f-14dcbc0a8ea3", "csrPem": "string", "active": false}How would you rate this page?
Retrieve a holder root CA certificate revocation list GET
Retrieves the Certificate Revocation List (CRL) for a managed holder root CA certificate, as a DER-encoded binary document. This endpoint is only available for managed roots — for unmanaged roots it returns `404 NoCertificateRevocationList`.
Retrieve all wallet attestation signers GET
Retrieves all wallet attestation signers for the tenant across all roots. The response may contain a mix of: - CSR-pending signers (unmanaged, certificate not yet uploaded) - Active signers (managed or unmanaged with an uploaded certificate) ### **Analytic events** * CREDENTIAL_HOLDER_WALLET_ATTESTATION_SIGNER_CERTIFICATE_RETRIEVE_LIST_START * CREDENTIAL_HOLDER_WALLET_ATTESTATION_SIGNER_CERTIFICATE_RETRIEVE_LIST_SUCCESS * CREDENTIAL_HOLDER_WALLET_ATTESTATION_SIGNER_CERTIFICATE_RETRIEVE_LIST_FAIL