Default Requests

Every attestation request repeats the same client ID and lifetime. Default requests let you save them once on your Client Attestation Service, so each request only sends the instance public key.

Default requests are optional. Nothing on this page is required to issue attestations.

What Changes

Without a default, a request carries clientId, instancePublicKeyJwk and, if you want a lifetime other than 24 hours, expirationSeconds. With both stored, the call becomes:

{
  "instancePublicKeyJwk": {
    "kty": "EC",
    "crv": "P-256",
    "x": "WKn-ZIGevcwGIyyrzFoZNBdaq9_TsqzGl96oc0CWuis",
    "y": "y77t-RvAHRKTsSGdIYUfweuOvwrvDD-Q3Hv5J0fSKbE"
  }
}

Anything you do send in the call wins over the stored value.

attestationValiditySeconds on the service is not a fallback for direct calls to the attest endpoint. Such a call uses its own expirationSeconds, which is 86400 (24 hours) unless you send another value. A stored default is how you change that. The service setting applies when a Wallet2 service requests attestations for itself.

Prerequisites

  • A Client Attestation Service with its KMS attached. See Setup.
  • A bearer token with the update-default-requests permission and the permission to request attestations. Both are needed to store a default.

Step 1: Store a Default

The last part of the URL, attest-client, names the API call the default applies to: the one behind POST /v1/{target}/client-attester-api/attest.

CURL

Endpoint: PUT /v1/{target}/client-attester-api/default-requests/attest-client | API Reference

Example Request
curl -X 'PUT' \
  'https://{orgID}.enterprise-sandbox.waltid.dev/v1/{target}/client-attester-api/default-requests/attest-client' \
  -H 'accept: application/json' \
  -H 'Authorization: Bearer {yourToken}' \
  -H 'Content-Type: application/json' \
  -d '{
  "clientId": "waltid.tenant1.wallet1",
  "expirationSeconds": 3600
}'

Path Parameters

  • orgID: String (required) - Organization host alias.
  • target: resourceIdentifier (required) - {organizationID}.{tenantID}.{clientAttesterServiceID}, for example waltid.tenant1.client-attester1.

Header Parameters

  • Authorization: String (required) - Bearer token. Format: Bearer {yourToken}.

Body Parameters

  • A partial attestation request (clientId, instancePublicKeyJwk, expirationSeconds). Unknown or misspelled keys are rejected now, not when you request an attestation.
Example Response 200 OK

The stored document is echoed back.

{
  "clientId": "waltid.tenant1.wallet1",
  "expirationSeconds": 3600
}

Response Codes

  • 200 - Default request stored.
  • 400 - The document is not a valid partial body for this operation.
  • 401 / 403 - Authentication or authorization failure.

Step 2: Request an Attestation

Send only the instance key.

CURL

Endpoint: POST /v1/{target}/client-attester-api/attest | API Reference

Example Request
curl -X 'POST' \
  'https://{orgID}.enterprise-sandbox.waltid.dev/v1/{target}/client-attester-api/attest' \
  -H 'accept: application/json' \
  -H 'Authorization: Bearer {yourToken}' \
  -H 'Content-Type: application/json' \
  -d '{
  "instancePublicKeyJwk": {
    "kty": "EC",
    "crv": "P-256",
    "x": "WKn-ZIGevcwGIyyrzFoZNBdaq9_TsqzGl96oc0CWuis",
    "y": "y77t-RvAHRKTsSGdIYUfweuOvwrvDD-Q3Hv5J0fSKbE"
  }
}'

Body Parameters

  • instancePublicKeyJwk: Object (required) - The instance public key. Any other field you send overrides the stored value.
Example Response 200 OK
{
  "clientAttestationJwt": "eyJ...",
  "expiresAt": 1790682000
}

The attestation's sub is the stored clientId, and it is valid for the stored expirationSeconds.

Response Codes

  • 200 - Attestation issued.
  • 400 - The merged request is invalid, for example when neither the default nor the call provides clientId.
  • 401 / 403 - Authentication or authorization failure.

Good to Know

  • clientId is required. Store it, or send it on every call.
  • Defaults are not guardrails. A caller can send their own clientId or expirationSeconds.
  • Explicit values win. A call with "expirationSeconds": 60 gets a 60-second attestation.

Read or Remove a Default

  • List all stored defaults: GET /v1/{target}/client-attester-api/default-requests (needs view-default-requests).
  • Read one: GET …/default-requests/attest-client. Returns 404 if none is stored.
  • Remove one: DELETE …/default-requests/attest-client. Returns 204, also when nothing was stored.

Full details and permissions: Default Requests.

Last updated on September 29, 2026