Overview
Establish which Credential Holder Apps are trusted to claim your credentials, and how MATTR VII supports per-app trust and encryption.
Overview
Before delivering a credential, you decide which Credential Holder Apps (digital wallet apps) are trusted to claim it. Establishing this trust keeps your credentials out of unknown, malicious, compromised, or non-compliant Holder app environments, and lets you configure app-specific features for the apps you recognize.
Today you set up your trusted apps by contacting MATTR. There are two ways to establish trust in a Holder app, at different assurance levels:
- Client ID (with white-listed redirect URLs): A lower-assurance method. You register the Holder app's client ID, and for the Authorization Code flow you white-list the redirect URLs it is allowed to use.
- Wallet Attestation: A stronger method, where the Holder app cryptographically proves its authenticity before claiming a credential.
Per-app features
Because trust is established per Holder app, some issuance features are configured per app as well. You need to know that a given Holder app supports a feature before you enable it for that app.
- Wallet Attestation: Require a Holder app to present a valid attestation before it can claim your credentials.
- End-to-End Encryption: Encrypt credential requests and responses to a specific Holder app, so intermediary servers cannot read them. This is configured on a per-app basis, so it depends on the app supporting it.
How would you rate this page?
Last updated on