Toggle trust authority
PUT/v2/config/digital-wallet/openid/trust-authority/:trustAuthorityId/disable
Enables or disables a trust authority. A disabled trust authority is not used for credential or verifier trust validation. Give the wanted end state in disabled. The ID in the path must be a UUID, so this operation does not change the two built-in trust lists.
Request
Path Parameters
Unique identifier of a trust authority of the organisation. The value must be a UUID, so the identifiers 0 and 1 of the two built-in trust lists are not valid here.
Header Parameters
Optional. Unique identifier of the sandbox organisation to use for this request. When you send this header, the service runs the operation in the context of the named sandbox organisation, that is, against the wallet of that sandbox organisation and not against the main wallet of the organisation. Leave the header out to use the main wallet.
The service reads this header only when you authenticate with a bearer access token. When you authenticate with an API key, the service takes the sandbox organisation from the API key and ignores this header. To run an API-key call in a sandbox organisation, bind the key to the sandbox organisation with PUT /v2/config/admin/apikey/{apiKeyId}/sandbox-org instead.
X-SubwalletId is the deprecated name of this header. The service continues to accept it, but X-SandboxOrgId wins if you send both headers.
The sandbox organisation must exist, must belong to your organisation and must be deployed. An unknown identifier, an identifier of a sandbox organisation that is not deployed, and an identifier that belongs to a different organisation all make the call fail with HTTP 400.
- application/json
Body
required
When true, the trust authority is disabled. When false, it is enabled.
Responses
- 200
- 400
- 401
- 500
The updated trust authority record.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
trustAuthority objectrequired
The trust authority after the change.
Unique identifier of the trust authority record. Records that the organisation created have a UUID. The two built-in trust lists have the identifiers 0 and 1, and you cannot read, update, toggle or delete them with the per-identifier operations.
Possible values: [ETSI_TL]
Type of the trust list. The service accepts ETSI_TL (ETSI TS 119 612 trusted list) only.
Location of the trust list. For the ETSI_TL type, this is the HTTP or HTTPS URL of the trusted list document.
Name of the trust authority. The value is an empty string when the create or update request gave no name.
When true, this trust authority is disabled and not used for credential or verifier trust validation. The two built-in trust lists always return false.
Unix timestamp (in seconds) when this trust authority was registered. The two built-in trust lists always return 0.
Unix timestamp (in seconds) when this trust authority was last modified. The two built-in trust lists always return 0.
{
"trustAuthority": {
"id": "b7d1f4a2-8c3e-4a91-9f52-0d3c6e7a1b45",
"type": "ETSI_TL",
"value": "https://raw.githubusercontent.com/EWC-consortium/ewc-trust-list/refs/heads/main/EWC-TL.xml",
"name": "EU Trust List",
"disabled": false,
"createdAt": 1747011600,
"updatedAt": 1747011600
}
}
Bad request. The disabled field is missing, the organisation or wallet cannot be resolved, or the trust authority does not exist.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Unauthorized
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Internal server error
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}