light-mode-image
Learn
Trusted Holder Apps

Overview

Establish which Credential Holder Apps are trusted to claim your credentials, and how MATTR VII supports per-app trust and encryption.

Overview

Before delivering a credential, you decide which Credential Holder Apps (digital wallet apps) are trusted to claim it. Establishing this trust keeps your credentials out of unknown, malicious, compromised, or non-compliant Holder app environments, and lets you configure app-specific features for the apps you recognize.

Today you set up your trusted apps by contacting MATTR. There are two ways to establish trust in a Holder app, at different assurance levels:

  • Client ID (with white-listed redirect URLs): A lower-assurance method. You register the Holder app's client ID, and for the Authorization Code flow you white-list the redirect URLs it is allowed to use.
  • Wallet Attestation: A stronger method, where the Holder app cryptographically proves its authenticity before claiming a credential.

Per-app features

Because trust is established per Holder app, some issuance features are configured per app as well. You need to know that a given Holder app supports a feature before you enable it for that app.

  • Wallet Attestation: Require a Holder app to present a valid attestation before it can claim your credentials.
  • End-to-End Encryption: Encrypt credential requests and responses to a specific Holder app, so intermediary servers cannot read them. This is configured on a per-app basis, so it depends on the app supporting it.

How would you rate this page?

Last updated on

On this page