Chapter 2 · 7/8
Receiving and presenting
A QR offer, a request, a consent screen: the journey from institution to wallet and from wallet to verifier.
5 min
The institution prepares the credential
Every field is sealed on its own (salted hash); then the institution signs the whole credential with its key.
The animated diagram above shows a credential's journey end to end. This page opens its two halves one by one: receiving a credential and presenting it. Both use open protocols the EU has chosen.
Receiving a credential
- The offer. The institution shows you a A message, usually a QR code or a link, by which an issuer invites a wallet to collect a credential.: a QR code on screen or a link on your phone. Sometimes a one-time code arrives over a separate channel (such as SMS) to confirm it is you.
- The wallet introduces itself. It presents its attestation, showing it is a compliant wallet, and the key the credential will be bound to.
- The institution issues. It checks the attestation against the trust list, signs the credential and sends it to the wallet as several single-use copies.
The technical name for these steps is An open protocol (OpenID Foundation) describing how a credential is issued safely from an institution to a wallet..
Presenting a credential
- The request.The verifier sends a request: "Is this person over 18?" or "Which programme did they graduate from?". The request is signed with the verifier's registered certificate.
- The consent screen. The wallet shows who is asking (by their registered name in the trust list), what they are asking for, and whether they are allowed to ask for it. You approve or decline.
- The response. Only the fields you approved are sent, using a fresh copy of the credential and a signature from your device key.
- The check. The verifier checks the signature, the trust list entry and the revocation status; the result arrives in seconds.
The technical name for these steps is An open protocol (OpenID Foundation) describing how a wallet presents credentials to a verifier..
Can a verifier ask for anything?
No. When a verifier registers, it declares which information it will request and for what purpose. That goes into the trust list. If a verifier asks for something outside its registration, the wallet warns you. Sites that overask become visible.
Summary
- Receiving: offer → wallet attestation → signed credential, as several single-use copies (OpenID4VCI).
- Presenting: signed request → consent screen → only chosen fields → checked in seconds (OpenID4VP).
- A verifier may ask only for what it registered; the wallet warns about anything more.
Go deeper
Technical details and binding rules: