You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: 1.1/openid-4-verifiable-presentations-1_1.md
+25-1Lines changed: 25 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1140,6 +1140,9 @@ Additional, more complex examples can be found in (#more_dcql_query_examples).
1140
1140
1141
1141
A VP Token is only returned if the corresponding Authorization Request contained a `dcql_query` parameter or a `scope` parameter representing a DCQL Query (as defined in #vp_token_request).
1142
1142
1143
+
The Wallet MUST return a VP Token only if the set of Presentations represented
1144
+
by the VP Token satisfies the requirements of the DCQL query according to (#dcql_query_lang_processing_rules).
1145
+
1143
1146
A VP Token can be returned in the Authorization Response or the Token Response depending on the Response Type used. See (#response_type_vp_token) for more details.
1144
1147
1145
1148
If the Response Type value is `vp_token`, the VP Token is returned in the Authorization Response. When the Response Type value is `vp_token id_token` and the `scope` parameter contains `openid`, the VP Token is returned in the Authorization Response alongside a Self-Issued ID Token as defined in [@!SIOPv2].
@@ -1161,8 +1164,27 @@ The behavior with respect to the VP Token is unspecified for any other individua
1161
1164
1162
1165
When a VP Token is returned, the respective response includes the following parameters:
1163
1166
1167
+
1164
1168
`vp_token`:
1165
-
: REQUIRED. This is a JSON-encoded object containing entries where the key is the `id` value used for a Credential Query in the DCQL query and the value is an array of one or more Presentations that match the respective Credential Query. When `multiple` is omitted, or set to `false`, the array MUST contain only one Presentation. There MUST NOT be any entry in the JSON-encoded object for optional Credential Queries when there are no matching Credentials for the respective Credential Query. Each Presentation is represented as a string or object, depending on the format as defined in (#format_specific_parameters). The same rules as above apply for encoding the Presentations.
1169
+
: REQUIRED. A JSON-encoded object subject to the following requirements:
1170
+
1171
+
* Each key MUST be the `id` of a Credential Query in the DCQL query.
1172
+
1173
+
* Each value MUST be an array containing one or more Presentations matching
1174
+
the corresponding Credential Query.
1175
+
1176
+
* When `multiple` is omitted or set to `false`, the array MUST contain exactly
1177
+
one Presentation.
1178
+
1179
+
* The object MUST NOT contain an entry for an optional Credential Query when
1180
+
there are no matching Credentials for that Credential Query.
1181
+
1182
+
* Each Presentation MUST be encoded as a string or object according to
1183
+
(#format_specific_parameters).
1184
+
1185
+
* The object MAY be empty only if the DCQL query can be satisfied without
1186
+
returning any Presentation according to
1187
+
(#dcql_query_lang_processing_rules).
1166
1188
1167
1189
Other parameters, such as `code` (from [@!RFC6749]), or `id_token` (from [@!OpenID.Core]), and `iss` (from [@RFC9207]) can be included in the response as defined in the respective specifications.
1168
1190
@@ -3665,3 +3687,5 @@ The technology described in this specification was made available from contribut
3665
3687
* Clarified that Multi-RP-sig section means Verifier Info instead of attestations
3666
3688
* Updated origin examples to remove trailing slash
3667
3689
* Clarified that request_uri_method is a case-sensitive string
3690
+
* Clarify that empty objects in VP Tokens cannot be used to signify an error response
0 commit comments