Docs · API reference
Wallet endpoints
The two routes a wallet calls. Merchants never call them — they are documented so you can recognise them in a trace.
Fetch the request object
GET/wallet/request/:sessionIdunauthenticated
Returns the JAR authorization request object for the session as a raw compact JWT
with Content-Type: application/oauth-authz-req+jwt — not JSON. This is
what request_uri inside wallet_uri points at. It is
unauthenticated by design: the unguessable session id in the path is the
capability.
Whether it is signed depends on the deployment. With request-signing keys
configured it is an ES256 JWS carrying the certificate chain in x5c;
without them it is an Unsecured JWT (alg: "none") with an empty
signature.
Errors404 session_not_found 410 session_expired 429 rate_limit_exceeded 500 internal_error
Post the presentation
POST/wallet/response/:sessionIdunauthenticated
Accepts the wallet's presentation as an
application/x-www-form-urlencoded body — either a plaintext
direct_post body or an encrypted direct_post.jwt JWE,
depending on the configured response mode.
{ "redirect_uri": "https://your-site.example/verified#response_code=..." }redirect_uri is present when the session was created with
redirect_url. Both a completed and a failed verification return
200 here: the wallet cares about protocol success, not the verdict —
the verdict is what you read by polling, by webhook, or by redeeming the response
code.
Errors400 invalid_request 404 session_not_found 409 session_already_responded 410 session_expired 429 rate_limit_exceeded 500 internal_error