specs/credentials/shared/v0_1/credentials
library
Classes
-
CredentialReference
-
A pointer to an issued credential, without the credential itself. The counterpart
to IssuedCredential, for the far more common case of reading about a credential
rather than being handed one. A listing that embedded the signed credential in
every row would grow with the size of the credentials rather than the number of
them — a page of fifty is megabytes — and a reader that only needs to know a
credential exists, when it lapses, and how to revoke it does not need the bytes.
The holder can always fetch the credential itself by
credentialId, and a verifier
can check revocation from the row's status-list slot without either. Reach for
IssuedCredential only at the moment of minting, where the caller has no other way
to receive what was just made for them.
-
IssuedCredential
-
The receipt for a successfully-minted Verifiable Credential: a stable handle for
revocation and audit, the signed credential itself, and when it lapses. SCOPE —
this is an issuance receipt, returned by the party that minted the credential. It
is not the shape for a delivery receipt, where a holder hands an already-issued
credential to a party that stores it: such a task returns a receipt naming what was
stored (see vtc/members/vmc and vtc/join-requests/accept) and MUST NOT echo the
credential back to the party that just sent it. Reaching for this definition on a
delivery task is the mistake this paragraph exists to prevent.
additionalProperties is false, so a specification needing extra members cannot
compose this by $ref — allOf evaluates each subschema against the whole object
and this one would reject them. vta/credentials/issue is that case: its response is
this shape plus supersedes and ext, and it therefore states the members inline
while $ref-ing the shared CredentialId. That is deliberate, not drift.
-
RevocationReceipt
-
The receipt for a successful revocation. Consumers MUST report the family's
alreadyRevoked / already_revoked error when the credential was already revoked,
rather than returning a second receipt silently — the caller has to be able to
distinguish "I revoked it now" from "it was already gone". The counterpart to
IssuedCredential: both concern a credential's lifecycle at its issuer.
Typedefs
-
CredentialId
= String
-
Stable identifier for an issued credential — the handle for revocation and audit.
Opaque to the holder: it MUST be echoed verbatim when revoking and MUST NOT be
parsed.