Skip to main content

Create trust authority

POST 

/v2/config/digital-wallet/openid/trust-authority

Creates a trust authority for the organisation. A trust authority points to a trust list. The service uses the trust lists to validate issuers and verifiers in OID4VCI and OpenID4VP flows.

Request

Header Parameters

    X-SandboxOrgId stringrequired

    Optional. Unique identifier of the sandbox organisation to use for this request. When you send this header, the service runs the operation in the context of the named sandbox organisation, that is, against the wallet of that sandbox organisation and not against the main wallet of the organisation. Leave the header out to use the main wallet.

    The service reads this header only when you authenticate with a bearer access token. When you authenticate with an API key, the service takes the sandbox organisation from the API key and ignores this header. To run an API-key call in a sandbox organisation, bind the key to the sandbox organisation with PUT /v2/config/admin/apikey/{apiKeyId}/sandbox-org instead.

    X-SubwalletId is the deprecated name of this header. The service continues to accept it, but X-SandboxOrgId wins if you send both headers.

    The sandbox organisation must exist, must belong to your organisation and must be deployed. An unknown identifier, an identifier of a sandbox organisation that is not deployed, and an identifier that belongs to a different organisation all make the call fail with HTTP 400.

    Example: 6889e1a4c5b2f30001a3d710

Body

required

The trust list to add to the organisation.

    type stringrequired

    Possible values: [ETSI_TL]

    Type of the trust list. The service accepts ETSI_TL only. ETSI_TL is an ETSI Trusted List in XML format. The service changes the value to upper case.

    value stringrequired

    Possible values: non-empty and <= 2048 characters

    Location of the trust list. For the ETSI_TL type, give an HTTP or HTTPS URL that returns the trusted list document.

    name string

    Possible values: <= 255 characters

    Name of the trust authority. The service shows this name in the dashboard. This field is optional, and the service stores an empty string when you leave it out.

Responses

The service created the trust authority.

Response Headers
    Schema
      trustAuthority objectrequired

      The trust authority that the service created.

      id stringrequired

      Unique identifier of the trust authority record. Records that the organisation created have a UUID. The two built-in trust lists have the identifiers 0 and 1, and you cannot read, update, toggle or delete them with the per-identifier operations.

      type stringrequired

      Possible values: [ETSI_TL]

      Type of the trust list. The service accepts ETSI_TL (ETSI TS 119 612 trusted list) only.

      value stringrequired

      Location of the trust list. For the ETSI_TL type, this is the HTTP or HTTPS URL of the trusted list document.

      name stringrequired

      Name of the trust authority. The value is an empty string when the create or update request gave no name.

      disabled booleanrequired

      When true, this trust authority is disabled and not used for credential or verifier trust validation. The two built-in trust lists always return false.

      createdAt numberrequired

      Unix timestamp (in seconds) when this trust authority was registered. The two built-in trust lists always return 0.

      updatedAt numberrequired

      Unix timestamp (in seconds) when this trust authority was last modified. The two built-in trust lists always return 0.

    Loading...