IssuerEncryptionService
class IssuerEncryptionService @JvmOverloads constructor(encryptCredentialResponse: EncryptJweFun = EncryptJwe(), requireResponseEncryption: Boolean = false, supportedJweAlgorithms: Set<JweAlgorithm> = setOf(JweAlgorithm.ECDH_ES), supportedJweEncryptionAlgorithms: Set<JweEncryption> = setOf(JweEncryption.A256GCM), requireRequestEncryption: Boolean = false, decryptionKeyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), decryptCredentialRequest: DecryptJweFun? = DecryptJwe(decryptionKeyMaterial))(source)
Server implementation to handle credential request decryption and credential response encryption using OID4VCI.
Implemented from OpenID for Verifiable Credential Issuance 1.0 from 2025-09-16.
Constructors
Link copied to clipboard
constructor(encryptCredentialResponse: EncryptJweFun = EncryptJwe(), requireResponseEncryption: Boolean = false, supportedJweAlgorithms: Set<JweAlgorithm> = setOf(JweAlgorithm.ECDH_ES), supportedJweEncryptionAlgorithms: Set<JweEncryption> = setOf(JweEncryption.A256GCM), requireRequestEncryption: Boolean = false, decryptionKeyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), decryptCredentialRequest: DecryptJweFun? = DecryptJwe(decryptionKeyMaterial))
Properties
Link copied to clipboard
Advertised whenever we are able to decrypt credential requests. Requiring response encryption implies requiring request encryption, since the client's response encryption key may only be sent in an encrypted request.
Link copied to clipboard
Advertised unconditionally: we can always encrypt a response to the key the client sends us.