Get started

Docs · API reference

Wallet endpoints

The two routes a wallet calls. Merchants never call them — they are documented so you can recognise them in a trace.

Fetch the request object

GET/wallet/request/:sessionIdunauthenticated

Returns the JAR authorization request object for the session as a raw compact JWT with Content-Type: application/oauth-authz-req+jwt — not JSON. This is what request_uri inside wallet_uri points at. It is unauthenticated by design: the unguessable session id in the path is the capability.

Whether it is signed depends on the deployment. With request-signing keys configured it is an ES256 JWS carrying the certificate chain in x5c; without them it is an Unsecured JWT (alg: "none") with an empty signature.

Errors404 session_not_found 410 session_expired 429 rate_limit_exceeded 500 internal_error

Post the presentation

POST/wallet/response/:sessionIdunauthenticated

Accepts the wallet's presentation as an application/x-www-form-urlencoded body — either a plaintext direct_post body or an encrypted direct_post.jwt JWE, depending on the configured response mode.

200 OK
{ "redirect_uri": "https://your-site.example/verified#response_code=..." }

redirect_uri is present when the session was created with redirect_url. Both a completed and a failed verification return 200 here: the wallet cares about protocol success, not the verdict — the verdict is what you read by polling, by webhook, or by redeeming the response code.

Errors400 invalid_request 404 session_not_found 409 session_already_responded 410 session_expired 429 rate_limit_exceeded 500 internal_error