IssuerEncryptionService

class IssuerEncryptionService @JvmOverloads constructor(encryptCredentialResponse: EncryptJweFun = EncryptJwe(), requireResponseEncryption: Boolean = false, supportedJweAlgorithms: Set<JweAlgorithm> = setOf(JweAlgorithm.ECDH_ES), supportedJweEncryptionAlgorithms: Set<JweEncryption> = setOf(JweEncryption.A256GCM), requireRequestEncryption: Boolean = false, decryptionKeyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), decryptCredentialRequest: DecryptJweFun? = DecryptJwe(decryptionKeyMaterial))(source)

Server implementation to handle credential request decryption and credential response encryption using OID4VCI.

Implemented from OpenID for Verifiable Credential Issuance 1.0 from 2025-09-16.

Constructors

Link copied to clipboard
constructor(encryptCredentialResponse: EncryptJweFun = EncryptJwe(), requireResponseEncryption: Boolean = false, supportedJweAlgorithms: Set<JweAlgorithm> = setOf(JweAlgorithm.ECDH_ES), supportedJweEncryptionAlgorithms: Set<JweEncryption> = setOf(JweEncryption.A256GCM), requireRequestEncryption: Boolean = false, decryptionKeyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), decryptCredentialRequest: DecryptJweFun? = DecryptJwe(decryptionKeyMaterial))

Properties

Link copied to clipboard

Advertised whenever we are able to decrypt credential requests. Requiring response encryption implies requiring request encryption, since the client's response encryption key may only be sent in an encrypted request.

Link copied to clipboard

Advertised unconditionally: we can always encrypt a response to the key the client sends us.