Skip to content
← Back to app

Credential exchange

The holder-initiated delivery protocol: prove control of the key behind an identifier and collect the credential staged for it.

Collect a staged credential

The two-turn holder-initiated exchange: the holder asks the coordinator for the credential staged for its identifier, answers the identifier-control challenge by signing the fresh nonce with the key behind that identifier, and collects. The coordinator holds the certificate out-of-band; no key material is transmitted.

Generate a key first (Keys page).