[{"data":1,"prerenderedAt":1405},["ShallowReactive",2],{"/blog/product-update-32":3},{"id":4,"title":5,"archived":6,"author":7,"body":8,"category":1393,"coverImage":7,"description":1394,"extension":1395,"meta":1396,"navigation":1397,"ogImage":1398,"path":1399,"publishedAt":1400,"seo":1401,"stem":1402,"tags":1403,"__hash__":1404},"blog/blog/product-update-32.md","Product Update #32",false,"",{"type":9,"value":10,"toc":1375},"minimark",[11,19,35,40,52,55,60,83,92,97,117,123,126,130,133,146,150,155,160,168,175,179,184,247,253,258,316,322,327,378,384,389,403,408,471,475,480,512,517,540,545,559,564,573,575,579,591,594,597,602,609,626,632,637,645,651,656,672,678,683,686,692,697,700,706,711,714,720,725,741,745,765,769,793,796,799,804,822,827,856,860,866,897,902,924,927,964,967,990,994,999,1021,1024,1046,1049,1064,1069,1099,1104,1109,1158,1163,1171,1202,1207,1223,1228,1243,1248,1255,1260,1267,1272,1301,1306,1315,1319,1324,1326,1330,1333,1336,1343,1354,1361,1363,1371],[12,13,15],"h1",{"id":14},"tldr",[16,17,18],"strong",{},"TL;DR",[20,21,22,29],"ul",{},[23,24,25,28],"li",{},[16,26,27],{},"New release"," - Community & Enterprise Stack V1, Crypto2, and more.",[23,30,31,34],{},[16,32,33],{},"Events"," – OID4VCI/VP V1 and HAIP conformance test passing, France Identité Interop.",[36,37,39],"h2",{"id":38},"introducing-the-community-and-enterprise-stack-v1-editions","Introducing the Community and Enterprise Stack V1 Editions",[41,42,43,44,51],"p",{},"We are happy to announce the V1 of the ",[45,46,50],"a",{"href":47,"rel":48},"http://walt.id",[49],"nofollow","walt.id"," Community and Enterprise Stack.",[41,53,54],{},"Explore the latest version of our Issuer, Verifier and Wallet products, supporting OID4VCI and OID4VP v1 across our two stacks:",[41,56,57],{},[16,58,59],{},"Community Stack",[20,61,62,69,76],{},[23,63,64],{},[45,65,68],{"href":66,"rel":67},"https://docs.walt.id/community-stack/issuer2/getting-started",[49],"Issuer",[23,70,71],{},[45,72,75],{"href":73,"rel":74},"https://docs.walt.id/community-stack/verifier2/getting-started",[49],"Verifier",[23,77,78],{},[45,79,82],{"href":80,"rel":81},"https://docs.walt.id/community-stack/wallet2/getting-started",[49],"Wallet",[41,84,85,86,91],{},"Do you want build an end-to-end digital ID use case? Explore our new tutorial ",[45,87,90],{"href":88,"rel":89},"https://docs.walt.id/community-stack/home/tutorial-30-min-v2",[49],"here",".",[41,93,94],{},[16,95,96],{},"Enterprise Stack",[20,98,99,105,111],{},[23,100,101],{},[45,102,68],{"href":103,"rel":104},"https://docs.walt.id/enterprise-stack/services/issuer2-service/overview",[49],[23,106,107],{},[45,108,75],{"href":109,"rel":110},"https://docs.walt.id/enterprise-stack/services/verifier2-service/overview",[49],[23,112,113],{},[45,114,82],{"href":115,"rel":116},"https://docs.walt.id/enterprise-stack/services/wallet2-service/overview",[49],[41,118,85,119],{},[45,120,90],{"href":121,"rel":122},"https://docs.walt.id/enterprise-stack/home/tutorial-30-min-v2",[49],[41,124,125],{},"Changes for each stack since our last release can be found below.",[36,127,129],{"id":128},"community-stack-10","Community Stack (1.0)",[131,132],"hr",{},[41,134,135,136,140,141,91],{},"Below are the highlights available through 1.0 of the identity lib. Check out the full change log for v1.0 ",[45,137,90],{"href":138,"rel":139},"https://docs.walt.id/enterprise-stack/release-notes/releases/1.0.x",[49],". Want to learn more about the identity lib in general? Check out our ",[45,142,145],{"href":143,"rel":144},"https://youtu.be/5T7M63apfdg",[49],"intro video",[36,147,149],{"id":148},"_10","1.0",[151,152,154],"h3",{"id":153},"features","Features",[41,156,157],{},[16,158,159],{},"Crypto V2",[41,161,162,163,167],{},"We are happy to introduce crypto2, the next generation of our crypto lib for the ",[45,164,50],{"href":165,"rel":166},"http://walt.id/",[49]," stack. It re-architects key handling and extends multiplatform reach to more platforms incl. Android and iOS. It also introduces coroutine-native APIs, versioned key persistence, and pluggable software, device, remote-KMS, and HSM (PKCS#11) providers. A migration path for existing v1 keys is available.",[41,169,170,171,91],{},"Learn more ",[45,172,90],{"href":173,"rel":174},"https://github.com/walt-id/waltid-identity/tree/main/waltid-libraries/crypto/waltid-crypto2",[49],[151,176,178],{"id":177},"improvements","Improvements",[41,180,181],{},[16,182,183],{},"Verifier2 / OpenID4VP",[20,185,186,204,212,224],{},[23,187,188,189,193,194,197,198,203],{},"Made Verifier2 session bodies consistent: ",[190,191,192],"code",{},"core"," is now ",[190,195,196],{},"core_flow"," for every flow, including DC API (",[45,199,202],{"href":200,"rel":201},"https://github.com/walt-id/waltid-identity/pull/1821",[49],"#1821",").",[23,205,206,207,203],{},"Unified rate-limit configuration and applied it to verifier protocol endpoints (",[45,208,211],{"href":209,"rel":210},"https://github.com/walt-id/waltid-identity/pull/1994",[49],"#1994",[23,213,214,215,218,219,203],{},"Added signed-request nonce-binding coverage for ",[190,216,217],{},"request_uri"," POST (",[45,220,223],{"href":221,"rel":222},"https://github.com/walt-id/waltid-identity/pull/2015",[49],"#2015",[23,225,226,227,230,231,234,235,238,239,242,243,246],{},"Replaced annex labels with protocol names for verification session creation parameters. DC API sessions use ",[190,228,229],{},"dc_api_openid4vp"," (OpenID4VP Annex D) or ",[190,232,233],{},"dc_api_18013_7"," (ISO 18013-7 Annex C). For 18013-7, ",[190,236,237],{},"requestedElements"," is an alternative to ",[190,240,241],{},"dcql_query"," . (",[45,244,202],{"href":200,"rel":245},[49],")",[41,248,249,250,91],{},"Checkout the updated Verifier2 documentation ",[45,251,90],{"href":73,"rel":252},[49],[41,254,255],{},[16,256,257],{},"Wallet API 2",[20,259,260,274,280,288],{},[23,261,262,263,268,269,273],{},"Added isolated presentation endpoints (preview claims, reject, then build/submit) (",[45,264,267],{"href":265,"rel":266},"https://github.com/walt-id/waltid-identity/pull/1970",[49],"#1970","). You can also learn more ",[45,270,90],{"href":271,"rel":272},"https://docs.walt.id/community-stack/wallet2/credential-presenting/isolated-flow",[49]," in our docs.",[23,275,276,277,203],{},"Stored issuer and request metadata with received credentials (",[45,278,267],{"href":265,"rel":279},[49],[23,281,282,283,203],{},"Extended DID creation support in Wallet2 (",[45,284,287],{"href":285,"rel":286},"https://github.com/walt-id/waltid-identity/pull/1980",[49],"#1980",[23,289,290,291,294,295,300,301,300,306,311,312,91],{},"Wired transaction-data type profiles into Wallet2 present/preview/build/send, including ",[190,292,293],{},"urn:eudi:sca:payment:1",", and kept Wallet2 route-handler overloads binary-compatible (",[45,296,299],{"href":297,"rel":298},"https://github.com/walt-id/waltid-identity/pull/2084",[49],"#2084",", ",[45,302,305],{"href":303,"rel":304},"https://github.com/walt-id/waltid-identity/pull/2076",[49],"#2076",[45,307,310],{"href":308,"rel":309},"https://github.com/walt-id/waltid-identity/pull/2088",[49],"#2088","). You can learn more about the transaction data profiles ",[45,313,90],{"href":314,"rel":315},"https://docs.walt.id/community-stack/wallet2/configurations/config-files/transaction-data-profiles",[49],[41,317,318,319,91],{},"Checkout the updated Wallet2 documentation ",[45,320,90],{"href":80,"rel":321},[49],[41,323,324],{},[16,325,326],{},"Issuer / OpenID4VCI",[20,328,329,337,354,366],{},[23,330,331,332,203],{},"Published stage and failure events across the OpenID4VCI issuance flow so integrators can observe stalls (PIN, rejected wallet, unusable IdP response) instead of waiting for session expiry (",[45,333,336],{"href":334,"rel":335},"https://github.com/walt-id/waltid-identity/pull/2080",[49],"#2080",[23,338,339,340,343,344,347,348,353],{},"Consumed pre-authorized grants atomically so a second token request with the same code returns ",[190,341,342],{},"invalid_grant",". Invalid ",[190,345,346],{},"tx_code"," does not burn the grant (",[45,349,352],{"href":350,"rel":351},"https://github.com/walt-id/waltid-identity/pull/2074",[49],"#2074",") (Legacy Issuer, issuer2 already included this functionality)",[23,355,356,357,360,361,203],{},"Removed leftover issuer2 ",[190,358,359],{},"c_nonce"," compatibility paths (",[45,362,365],{"href":363,"rel":364},"https://github.com/walt-id/waltid-identity/pull/2010",[49],"#2010",[23,367,368,369,372,373,203],{},"Added EdDSA to the default ",[190,370,371],{},"proofSigningAlgValuesSupported"," (",[45,374,377],{"href":375,"rel":376},"https://github.com/walt-id/waltid-identity/pull/2008",[49],"#2008",[41,379,380,381,91],{},"Checkout the updated Issuer2 documentation ",[45,382,90],{"href":66,"rel":383},[49],[41,385,386],{},[16,387,388],{},"Trust Registry",[20,390,391],{},[23,392,393,394,397,398,203],{},"Added ETSI TS 119 612 national TSL and EU LoTL XML support, source-assurance/acceptance policies, and official schema validation. Removed legacy ",[45,395,50],{"href":165,"rel":396},[49]," JSON/XML pilot formats (",[45,399,402],{"href":400,"rel":401},"https://github.com/walt-id/waltid-identity/pull/1931",[49],"#1931",[41,404,405],{},[16,406,407],{},"Crypto / KMS / X.509",[20,409,410,423,435,447,455,463],{},[23,411,412,413,300,418,203],{},"Move to Crypto2 across the stack (KMS, credential-status signing, protocol crypto) and aligned ABI baselines for non-Android builds. Stored local v1 JWK keys migrate automatically; remote KMS keys stay on their cloud backends (",[45,414,417],{"href":415,"rel":416},"https://github.com/walt-id/waltid-identity/pull/1954",[49],"#1954",[45,419,422],{"href":420,"rel":421},"https://github.com/walt-id/waltid-identity/pull/2044",[49],"#2044",[23,424,425,426,429,430,203],{},"Stopped publishing Azure Key Vault / external-KMS URLs as JWT, JAR, JWKS, or DID ",[190,427,428],{},"kid"," values; public identifiers are JWK thumbprints or DID URL fragments (",[45,431,434],{"href":432,"rel":433},"https://github.com/walt-id/waltid-identity/pull/2031",[49],"#2031",[23,436,437,438,441,442,203],{},"Normalised Azure Key Vault EC ",[190,439,440],{},"signRaw"," output to ASN.1 DER, matching every other crypto backend (",[45,443,446],{"href":444,"rel":445},"https://github.com/walt-id/waltid-identity/pull/2072",[49],"#2072",[23,448,449,450,203],{},"Added an X.509 certificate util library for creating and signing CSRs and certificates (",[45,451,454],{"href":452,"rel":453},"https://github.com/walt-id/waltid-identity/pull/1901",[49],"#1901",[23,456,457,458,203],{},"Corrected the CWT status-list label (label 16) (",[45,459,462],{"href":460,"rel":461},"https://github.com/walt-id/waltid-identity/pull/2021",[49],"#2021",[23,464,465,466,203],{},"Returned clearer 400 messages when request bodies fail to decode (",[45,467,470],{"href":468,"rel":469},"https://github.com/walt-id/waltid-identity/pull/2014",[49],"#2014",[151,472,474],{"id":473},"breaking-changes","Breaking Changes",[41,476,477],{},[16,478,479],{},"Verifier2 session create",[20,481,482,495,503,509],{},[23,483,484,487,488,491,492,91],{},[190,485,486],{},"flow_type: \"dc_api\""," is removed. Use ",[190,489,490],{},"\"dc_api_openid4vp\""," or ",[190,493,494],{},"\"dc_api_18013_7\"",[23,496,497,498,193,500,502],{},"Nested config field ",[190,499,192],{},[190,501,196],{}," for all flows.",[23,504,505,508],{},[190,506,507],{},"expectedOrigins"," must be HTTPS secure-context origins (no trailing slash).",[23,510,511],{},"Omitting clientId on unsigned cross-device sessions now sets redirect_uri:\u003Cresponse_uri>. Signed requests must supply a real clientId (not the redirect_uri: prefix).",[41,513,514],{},[16,515,516],{},"Legacy Issuer API",[20,518,519,527],{},[23,520,521,522,524,525,91],{},"Pre-authorized codes without ",[190,523,346],{}," are single-use. A second token exchange returns ",[190,526,342],{},[23,528,529,532,533,536,537,203],{},[190,530,531],{},"POST /onboard/iso-mdl/document-signers",": ",[190,534,535],{},"iacaSigner"," requires the root CA PEM (",[45,538,454],{"href":452,"rel":539},[49],[41,541,542],{},[16,543,544],{},"External KMS / DID",[20,546,547,556],{},[23,548,549,550,552,553,203],{},"Published ",[190,551,428],{}," values are thumbprints / DID URLs, not vault or KMS locator URLs (",[45,554,434],{"href":432,"rel":555},[49],[23,557,558],{},"Newly issued did:jwk JWTs use kid {did}#0. Verifiers still accept older non-#0 kids (#2115, #2136).",[41,560,561],{},[16,562,563],{},"Certificates",[20,565,566],{},[23,567,568,569,572],{},"mdoc and SD-JWT profiles no longer share one end-entity certificate. mdoc uses a Document Signer leaf; SD-JWT uses a separate leaf. IACA stays a verifier trust anchor, not part of ",[190,570,571],{},"x5Chain"," (#2118).",[131,574],{},[36,576,578],{"id":577},"enterprise-stack-10","Enterprise Stack (1.0)",[41,580,581,582,586,587,91],{},"Below are the new feature highlights available through 1.0 of the Enterprise Stack. Check out the full change log for 1.0 ",[45,583,90],{"href":584,"rel":585},"https://docs.walt.id/enterprise-stack/release-notes/releases/0.22.x",[49],". Want to learn more about the enterprise stack in general? Check out our ",[45,588,145],{"href":589,"rel":590},"https://youtu.be/FKzoD9F23VE",[49],[36,592,149],{"id":593},"_10-1",[151,595,154],{"id":596},"features-1",[41,598,599],{},[16,600,601],{},"Wallet2 as the default wallet",[41,603,604,605,608],{},"Wallet2 capabilities are now available under the ",[190,606,607],{},"/v2"," paths. Updates include:",[20,610,611,617,620],{},[23,612,613,614,91],{},"Migrated Enterprise UI and protocol routes to Wallet2 under ",[190,615,616],{},"/v2/{target}/wallet-service-api/...",[23,618,619],{},"Added isolated presentation steps (preview claims, reject, then build/submit).",[23,621,622,623,625],{},"Added ",[190,624,293],{}," transaction-data support, authorized mdoc data types, and Wallet2 transaction-data profile discovery.",[41,627,628,629],{},"Checkout the new wallet2 docs ",[45,630,90],{"href":115,"rel":631},[49],[41,633,634],{},[16,635,636],{},"Verifier2",[20,638,639,642],{},[23,640,641],{},"Aligned verification-session create bodies across flow types, including Digital Credentials API.",[23,643,644],{},"Applied the shared rate-limit config to verifier protocol endpoints.",[41,646,647,648],{},"Checkout the updated Verifier2 docs ",[45,649,90],{"href":109,"rel":650},[49],[41,652,653],{},[16,654,655],{},"Issuer2",[20,657,658,661,666],{},[23,659,660],{},"Published stage and failure events across the OpenID4VCI issuance flow so integrators can observe why issuance stalled.",[23,662,663,664,91],{},"Added EdDSA to default ",[190,665,371],{},[23,667,668,669,671],{},"Removed leftover ",[190,670,359],{}," compatibility paths.",[41,673,674,675],{},"Checkout the updated Issuer2 docs ",[45,676,90],{"href":103,"rel":677},[49],[41,679,680],{},[16,681,682],{},"PKCS#11 Support",[41,684,685],{},"Store and use signing keys on a PKCS#11 token through the Enterprise Stack Key Management Service.",[41,687,170,688,91],{},[45,689,90],{"href":690,"rel":691},"https://docs.walt.id/enterprise-stack/services/key-management-service/pkcs11",[49],[41,693,694],{},[16,695,696],{},"eIDAS2 Audit Logging",[41,698,699],{},"The eIDAS Audit Log records compliance evidence for credential issuance and presentation verification in the Enterprise Stack.",[41,701,170,702,91],{},[45,703,90],{"href":704,"rel":705},"https://docs.walt.id/enterprise-stack/administration/events-and-metrics/eidas-audit-log/overview",[49],[41,707,708],{},[16,709,710],{},"Licensing",[41,712,713],{},"The Enterprise Stack now requires an active license to run. Choose an online activation via OpenID credential offer, or an offline .waltlicense bundle for air-gapped environments. The new /license/status endpoint gives super admins visibility into activation state, entitlements, and expiry.",[41,715,170,716,91],{},[45,717,90],{"href":718,"rel":719},"https://docs.walt.id/enterprise-stack/setup/licensing",[49],[41,721,722],{},[16,723,724],{},"General",[20,726,727,734],{},[23,728,729,730,91],{},"Added an endpoint to list all supported permissions. Learn more ",[45,731,90],{"href":732,"rel":733},"https://docs.walt.id/enterprise-stack/administration/access-and-permissions/permissions/overview",[49],[23,735,736,737,91],{},"Superadmin registration now uses a typed request object. Learn more ",[45,738,90],{"href":739,"rel":740},"https://docs.walt.id/enterprise-stack/administration/access-and-permissions/super-admin/activate",[49],[41,742,743],{},[16,744,407],{},[20,746,747,750,753,756,762],{},[23,748,749],{},"Moved KMS, credential-status signing (CWT/JWT/W3C), client attestation, and Issuer2/Verifier2/Wallet2 crypto features over to the new Crypto2 lib.",[23,751,752],{},"Stored local v1 JWK keys are migrated automatically; remote KMS keys stay attached through the Enterprise KMS adapter.",[23,754,755],{},"PKCS#11 / HSM and cloud KMS paths run on the Crypto2 backends.",[23,757,758,759,761],{},"Published JWT/JAR/JWKS/DID ",[190,760,428],{}," values for external KMS keys are JWK thumbprints or DID URLs, not cloud-KMS locator URLs.",[23,763,764],{},"Added X.509 certificate helpers (CSR and certificate create/sign). ISO mDL document-signer onboarding requires the IACA root CA PEM.",[151,766,768],{"id":767},"fixes-an-improvements","Fixes an improvements",[20,770,771,781,784,790],{},[23,772,773,774,777,778,91],{},"Mapped Wallet2 token-exchange failures to the upstream OAuth status (or ",[190,775,776],{},"502",") instead of a generic ",[190,779,780],{},"500",[23,782,783],{},"Friendlier 400 messages when request bodies fail to decode.",[23,785,786,787,789],{},"Covered retained KMS keys on verifier ",[190,788,217],{}," POST re-sign.",[23,791,792],{},"Corrected the CWT status-list content-type label (label 16).",[151,794,474],{"id":795},"breaking-changes-1",[41,797,798],{},"Review these before upgrading. Legacy v1 protocol routes can still be turned on with feature flags where noted.",[41,800,801],{},[16,802,803],{},"License required to run",[41,805,806,807,810,811,814,815,818,819,91],{},"The Enterprise API does not serve traffic without an active license. Unlicensed or restricted nodes return ",[190,808,809],{},"503"," on all routes except ",[190,812,813],{},"/livez",", login/logout, ",[190,816,817],{},"GET /license/status",", and usage-report export.  Learn more ",[45,820,90],{"href":718,"rel":821},[49],[41,823,824],{},[16,825,826],{},"Legacy services disabled by default",[20,828,829,846],{},[23,830,831,300,834,837,838,841,842,845],{},[16,832,833],{},"Issuer v1",[16,835,836],{},"Verifier v1",", and ",[16,839,840],{},"Wallet v1"," protocol routes are off unless the corresponding feature flag is enabled (",[190,843,844],{},"wallet-draft-routes"," for Wallet1).",[23,847,848,849,300,851,837,853,91],{},"New deployments should use ",[16,850,655],{},[16,852,636],{},[16,854,855],{},"Wallet2",[41,857,858],{},[16,859,82],{},[41,861,862,865],{},[190,863,864],{},"init-wallet"," removed",[20,867,868,874,885],{},[23,869,870,871],{},"Old: ",[190,872,873],{},"POST /v1/{org}.{tenant}/wallet-service-api/init-wallet",[23,875,876,877,880,881,884],{},"New: ",[190,878,879],{},"POST /v1/{org}.{tenant}/resource-api/services/init"," with a composable ",[190,882,883],{},"wallet"," payload (optional KMS, DID store/service, credential store).",[23,886,887,888,890,891,894,895,91],{},"Response is a ",[190,889,883],{}," result object. The service type is ",[190,892,893],{},"wallet2",", not ",[190,896,883],{},[41,898,899,900],{},"Protocol routes moved to ",[190,901,607],{},[20,903,904,912],{},[23,905,906,907,894,909,91],{},"Wallet2 receive, present, client attestation, and dependency routes are ",[190,908,616],{},[190,910,911],{},"/v1",[23,913,914,915,300,918,300,921,91],{},"Examples: ",[190,916,917],{},".../credentials/receive/pre-authorized",[190,919,920],{},".../credentials/present",[190,922,923],{},".../client-attestation/obtain",[41,925,926],{},"Receive body and response",[20,928,929,939,957],{},[23,930,931,934,935,938],{},[190,932,933],{},"useClientAttestation"," and ",[190,936,937],{},"runPolicies"," are no longer request fields. Client attestation is used automatically when the issuer advertises it and the wallet has a linked client attester.",[23,940,941,942,945,946,949,950,953,954,91],{},"Provide ",[190,943,944],{},"offerUrl"," (or ",[190,947,948],{},"offerJson",") and optional ",[190,951,952],{},"keyReference"," / ",[190,955,956],{},"did",[23,958,959,960,963],{},"Response is an object ",[190,961,962],{},"{ \"credentialIds\": [...], \"deferredTransactionIds\": {} }",", not an array of stored credentials.",[41,965,966],{},"Present body",[20,968,969,977,984],{},[23,970,971,193,974,976],{},[190,972,973],{},"didReference",[190,975,956],{}," (inline DID string or DID-store reference).",[23,978,979,980,983],{},"The full-flow present endpoint no longer accepts a ",[190,981,982],{},"credentials"," array; it DCQL-matches from the wallet credential store.",[23,985,986,987,91],{},"To present inline credentials, use ",[190,988,989],{},"POST /v2/{wallet}/wallet-service-api/credentials/present/isolated",[41,991,992],{},[16,993,636],{},[41,995,899,996],{},[190,997,998],{},"/v2/.../verifier-service-api",[20,1000,1001,1006,1011],{},[23,1002,870,1003],{},[190,1004,1005],{},"/v1/{target}/verifier2-service-api/{endpoint}",[23,1007,876,1008],{},[190,1009,1010],{},"/v2/{target}/verifier-service-api/{endpoint}",[23,1012,1013,1014,1017,1018,91],{},"Service create is unchanged: ",[190,1015,1016],{},"POST /v1/{target}/resource-api/services/create"," with ",[190,1019,1020],{},"\"type\": \"verifier2\"",[41,1022,1023],{},"DC API session body",[20,1025,1026,1034,1041],{},[23,1027,1028,487,1030,491,1032,91],{},[190,1029,486],{},[190,1031,490],{},[190,1033,494],{},[23,1035,1036,1037,894,1039,91],{},"Nested config field is ",[190,1038,196],{},[190,1040,192],{},[23,1042,1043,1045],{},[190,1044,507],{}," must be HTTPS secure-context origins (no trailing slash). HTTP local origins are rejected.",[41,1047,1048],{},"Client ID",[20,1050,1051],{},[23,1052,1053,1054,1057,1058,1061,1062,91],{},"Omitting ",[190,1055,1056],{},"clientId"," on unsigned cross-device sessions now sets ",[190,1059,1060],{},"redirect_uri:\u003Cresponse_uri>",". Signed requests must supply a real ",[190,1063,1056],{},[41,1065,1066],{},[16,1067,1068],{},"DID service",[20,1070,1071,1086,1093],{},[23,1072,1073,1074,953,1077,1080,1081,953,1083,91],{},"Create DID fields ",[190,1075,1076],{},"keyId",[190,1078,1079],{},"keyIdSet"," are now ",[190,1082,952],{},[190,1084,1085],{},"keyReferenceSet",[23,1087,1088,1089,1092],{},"You may pass an inline ",[190,1090,1091],{},"key"," (JWK) instead of a stored-key reference.",[23,1094,1095,1096,203],{},"URLs unchanged (",[190,1097,1098],{},"POST /v1/{did-service}/did-service-api/dids/create/key|jwk|web",[41,1100,1101],{},[16,1102,1103],{},"Superadmin registration",[20,1105,1106],{},[23,1107,1108],{},"The registration token is no longer a raw string. Send:",[1110,1111,1115],"pre",{"className":1112,"code":1113,"language":1114,"meta":7,"style":7},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"token\": \"superadmin-token\"\n}\n","json",[190,1116,1117,1126,1152],{"__ignoreMap":7},[1118,1119,1122],"span",{"class":1120,"line":1121},"line",1,[1118,1123,1125],{"class":1124},"sMK4o","{\n",[1118,1127,1129,1132,1136,1139,1142,1145,1149],{"class":1120,"line":1128},2,[1118,1130,1131],{"class":1124},"  \"",[1118,1133,1135],{"class":1134},"spNyl","token",[1118,1137,1138],{"class":1124},"\"",[1118,1140,1141],{"class":1124},":",[1118,1143,1144],{"class":1124}," \"",[1118,1146,1148],{"class":1147},"sfazB","superadmin-token",[1118,1150,1151],{"class":1124},"\"\n",[1118,1153,1155],{"class":1120,"line":1154},3,[1118,1156,1157],{"class":1124},"}\n",[41,1159,1160],{},[16,1161,1162],{},"Service dependencies",[20,1164,1165],{},[23,1166,1167,1170],{},[190,1168,1169],{},"POST .../dependencies/add"," no longer accepts a raw path string. Send:",[1110,1172,1174],{"className":1112,"code":1173,"language":1114,"meta":7,"style":7},"{\n  \"dependency\": \"org.tenant.kms\"\n}\n",[190,1175,1176,1180,1198],{"__ignoreMap":7},[1118,1177,1178],{"class":1120,"line":1121},[1118,1179,1125],{"class":1124},[1118,1181,1182,1184,1187,1189,1191,1193,1196],{"class":1120,"line":1128},[1118,1183,1131],{"class":1124},[1118,1185,1186],{"class":1134},"dependency",[1118,1188,1138],{"class":1124},[1118,1190,1141],{"class":1124},[1118,1192,1144],{"class":1124},[1118,1194,1195],{"class":1147},"org.tenant.kms",[1118,1197,1151],{"class":1124},[1118,1199,1200],{"class":1120,"line":1154},[1118,1201,1157],{"class":1124},[41,1203,1204],{},[16,1205,1206],{},"Dev setup",[20,1208,1209],{},[23,1210,1211,1214,1215,1218,1219,1222],{},[190,1212,1213],{},"POST /v1/admin/initial-setup"," is gone. Use ",[190,1216,1217],{},"POST /v1/dev/initial-setup"," (requires the ",[190,1220,1221],{},"dev-mode"," feature).",[41,1224,1225],{},[16,1226,1227],{},"Data Retention service removed",[20,1229,1230],{},[23,1231,1232,1233,1238,1239,91],{},"Session and OAuth artefact expiry is handled by ",[16,1234,1235],{},[16,1236,1237],{},"data ejection"," / TTLs. Remove Data Retention service configuration and calls. Learn more ",[45,1240,90],{"href":1241,"rel":1242},"https://docs.walt.id/enterprise-stack/setup/configurations/config-files/session-data-ejection",[49],[41,1244,1245],{},[16,1246,1247],{},"External KMS key IDs",[20,1249,1250],{},[23,1251,549,1252,1254],{},[190,1253,428],{}," values in JWT, JAR, JWKS, and DID documents are thumbprints or DID URLs, not vault/KMS locator URLs.",[41,1256,1257],{},[16,1258,1259],{},"ISO mDL document-signer onboarding",[20,1261,1262],{},[23,1263,1264,1266],{},[190,1265,535],{}," requires the IACA root CA PEM.",[41,1268,1269],{},[16,1270,1271],{},"X.509 certificate store",[20,1273,1274,1280,1286],{},[23,1275,1276,1279],{},[190,1277,1278],{},"PUT /v1/{target}/x509-store-api/certificates"," inserts or updates and returns the certificate.",[23,1281,1282,1285],{},[190,1283,1284],{},"POST /v1/{target}/x509-store-api/certificates"," inserts only and fails if the certificate id already exists.",[23,1287,1288,1289,1292,1293,1296,1297,1300],{},"The store no longer validates the certificate. ",[190,1290,1291],{},"type"," is ignored. Use ",[190,1294,1295],{},"metadata"," instead of deprecated ",[190,1298,1299],{},"complementaryMetadata"," for VICAL entries.",[41,1302,1303],{},[16,1304,1305],{},"eIDAS audit",[20,1307,1308],{},[23,1309,1310,1311,1314],{},"The durable eIDAS audit log is off unless the ",[190,1312,1313],{},"eidas-audit"," feature is enabled. Audit HTTP routes are absent when the feature is off.",[41,1316,1317],{},[16,1318,563],{},[20,1320,1321],{},[23,1322,1323],{},"mdoc and SD-JWT issuance examples/profiles no longer share one end-entity certificate. mdoc uses a Document Signer leaf; SD-JWT uses a separate leaf. IACA stays a verifier trust anchor, not part of `x5Chain",[131,1325],{},[36,1327,1329],{"id":1328},"oid4vcivp-v1-haip-compliance","OID4VCI/VP V1 & HAIP Compliance",[41,1331,1332],{},"Our latest Verifier and Issuer successfully passed the official conformance tests for OpenID4VCI, OpenID4VP and the OpenID4VC HAIP profiles.",[41,1334,1335],{},"Our wallet APIs and SDK also pass the official conformance tests for OpenID4VCI and OpenID4VP, as well as select test plans for OpenID4VC HAIP (support will be expanded via future releases)",[36,1337,1339,1342],{"id":1338},"waltid-x-france-identité-wallet",[45,1340,50],{"href":165,"rel":1341},[49]," x France Identité Wallet",[41,1344,1345,1346,1349,1350,91],{},"The ",[45,1347,50],{"href":165,"rel":1348},[49]," Verifier now works with the France Identité Wallet. Verify PIDs and Age Verification Credentials. Learn more about on the France Identité marketplace ",[45,1351,90],{"href":1352,"rel":1353},"https://playground.france-identite.gouv.fr/marketplace/issuers/waltid/",[49],[41,1355,1356],{},[45,1357,1360],{"href":1358,"rel":1359},"https://youtu.be/t7dI1t5Bfu0",[49],"Watch the video",[131,1362],{},[41,1364,1365,1366],{},"PS: If you enjoy working with our tools, make sure to leave us a ⭐ ",[45,1367,1370],{"href":1368,"rel":1369},"https://github.com/walt-id/waltid-identity",[49],"on GitHub",[1372,1373,1374],"style",{},"html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":7,"searchDepth":1128,"depth":1128,"links":1376},[1377,1378,1379,1384,1385,1390,1391],{"id":38,"depth":1128,"text":39},{"id":128,"depth":1128,"text":129},{"id":148,"depth":1128,"text":149,"children":1380},[1381,1382,1383],{"id":153,"depth":1154,"text":154},{"id":177,"depth":1154,"text":178},{"id":473,"depth":1154,"text":474},{"id":577,"depth":1128,"text":578},{"id":593,"depth":1128,"text":149,"children":1386},[1387,1388,1389],{"id":596,"depth":1154,"text":154},{"id":767,"depth":1154,"text":768},{"id":795,"depth":1154,"text":474},{"id":1328,"depth":1128,"text":1329},{"id":1338,"depth":1128,"text":1392},"walt.id x France Identité Wallet","Product Updates","Community & Enterprise Stack V1, OID4VCI/VP V1 and HAIP conformance and more","md",{},true,null,"/blog/product-update-32","2026-08-25",{"title":5,"description":1394},"blog/product-update-32",[],"gqeIlx8Wd9IoE_7k2adxKw8NvYo1l5FV3gKmeYyECy4",1787813323307]