Update holder global configuration
PUT/v2/config/digital-wallet/openid/holder/global-configuration/:globalConfigurationId
Updates a holder global configuration for OID4VCI and OpenID4VP flows. The wallet replaces all settings with the values in the request body, so send every field that you want to keep.
This is the only operation that sets redirectUrl. The wallet stores a new value of requirePushedAuthorizationRequests, but the response and the later read and list operations can still give the value from before this update.
Request
Path Parameters
Unique identifier of the global configuration. Give globalConfigurationId for the issuer operations, holderGlobalConfigurationId for the holder operations, and verifierGlobalConfigurationId for the verifier operations. Do not give the id field of the record.
Header Parameters
Optional. Unique identifier of the sandbox organisation to use for this request. When you send this header, the service runs the operation in the context of the named sandbox organisation, that is, against the wallet of that sandbox organisation and not against the main wallet of the organisation. Leave the header out to use the main wallet.
The service reads this header only when you authenticate with a bearer access token. When you authenticate with an API key, the service takes the sandbox organisation from the API key and ignores this header. To run an API-key call in a sandbox organisation, bind the key to the sandbox organisation with PUT /v2/config/admin/apikey/{apiKeyId}/sandbox-org instead.
X-SubwalletId is the deprecated name of this header. The service continues to accept it, but X-SandboxOrgId wins if you send both headers.
The sandbox organisation must exist, must belong to your organisation and must be deployed. An unknown identifier, an identifier of a sandbox organisation that is not deployed, and an identifier that belongs to a different organisation all make the call fail with HTTP 400.
- application/json
Body
required
New settings for the holder global configuration. Give all fields, because the wallet replaces the full configuration.
When true, the wallet accepts encrypted OID4VCI Credential Responses. You must give this field.
Interval in seconds between two credential revocation status checks. Use 0 to stop the automatic checks.
Redirect URL that the wallet sends in the OAuth 2.0 Authorization Request during OID4VCI credential issuance.
Default value: false
When true, the wallet uses a Pushed Authorization Request (PAR) for the OID4VCI Authorization Code flow. The service uses false when you leave this field out.
Responses
- 200
- 400
- 401
- 500
The wallet updated the holder global configuration.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
holderGlobalConfiguration object
Global configuration of the holder wallet. It holds the settings that every OID4VCI and OpenID4VP flow of the organisation uses.
Record identifier of the holder global configuration. The service makes this value when it saves the record. It is not the same value as holderGlobalConfigurationId.
Unique identifier of the holder global configuration. Give this value in the path of the read, update and delete operations.
Identifier of the digital wallet deployment that holds this configuration.
When true, the wallet accepts encrypted OID4VCI Credential Responses.
Interval in seconds between two credential revocation status checks.
Redirect URL that the wallet sends in the OAuth 2.0 Authorization Request during OID4VCI credential issuance. The create operation always returns an empty string, because the service sets this value only through the update operation.
When true, the wallet uses a Pushed Authorization Request (PAR, RFC 9126) for the OID4VCI Authorization Code flow. The read, update and list operations can return the value from before the last update. See the update operation.
Unix timestamp (in seconds) when this configuration was created.
Unix timestamp (in seconds) when this configuration was last modified.
{
"holderGlobalConfiguration": {
"id": "665f2b8c9a1d4e0012ab34cd",
"holderGlobalConfigurationId": "b7d1f4a2-8c3e-4a91-9f52-0d3c6e7a1b45",
"openIdOrganisationId": "string",
"supportCredentialEncryption": true,
"refreshCredentialStatusInterval": 3600,
"redirectUrl": "https://wallet.example.com/callback",
"requirePushedAuthorizationRequests": false,
"createdAt": 1747011600,
"updatedAt": 1747011600
}
}
The request body does not give supportCredentialEncryption, or the configuration ID is unknown.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Unauthorized
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Internal server error
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}