Default Requests
Every attestation request repeats the same client ID and lifetime. Default requests let you save them once on your Client Attestation Service, so each request only sends the instance public key.
Default requests are optional. Nothing on this page is required to issue attestations.
What Changes
Without a default, a request carries clientId, instancePublicKeyJwk and, if you want a lifetime other than 24 hours, expirationSeconds. With both stored, the call becomes:
{
"instancePublicKeyJwk": {
"kty": "EC",
"crv": "P-256",
"x": "WKn-ZIGevcwGIyyrzFoZNBdaq9_TsqzGl96oc0CWuis",
"y": "y77t-RvAHRKTsSGdIYUfweuOvwrvDD-Q3Hv5J0fSKbE"
}
}
Anything you do send in the call wins over the stored value.
attestationValiditySeconds on the service is not a fallback for direct calls to the attest endpoint. Such a call uses its own expirationSeconds, which is 86400 (24 hours) unless you send another value. A stored default is how you change that. The service setting applies when a Wallet2 service requests attestations for itself.
Prerequisites
- A Client Attestation Service with its KMS attached. See Setup.
- A bearer token with the
update-default-requestspermission and the permission to request attestations. Both are needed to store a default.
Step 1: Store a Default
The last part of the URL, attest-client, names the API call the default applies to: the one behind POST /v1/{target}/client-attester-api/attest.
Endpoint: PUT /v1/{target}/client-attester-api/default-requests/attest-client | API Reference
Example Request
curl -X 'PUT' \
'https://{orgID}.enterprise-sandbox.waltid.dev/v1/{target}/client-attester-api/default-requests/attest-client' \
-H 'accept: application/json' \
-H 'Authorization: Bearer {yourToken}' \
-H 'Content-Type: application/json' \
-d '{
"clientId": "waltid.tenant1.wallet1",
"expirationSeconds": 3600
}'
Path Parameters
- orgID: String (required) - Organization host alias.
- target: resourceIdentifier (required) -
{organizationID}.{tenantID}.{clientAttesterServiceID}, for examplewaltid.tenant1.client-attester1.
Header Parameters
- Authorization: String (required) - Bearer token. Format:
Bearer {yourToken}.
Body Parameters
- A partial attestation request (
clientId,instancePublicKeyJwk,expirationSeconds). Unknown or misspelled keys are rejected now, not when you request an attestation.
Example Response 200 OK
The stored document is echoed back.
{
"clientId": "waltid.tenant1.wallet1",
"expirationSeconds": 3600
}
Response Codes
200- Default request stored.400- The document is not a valid partial body for this operation.401/403- Authentication or authorization failure.
Step 2: Request an Attestation
Send only the instance key.
Endpoint: POST /v1/{target}/client-attester-api/attest | API Reference
Example Request
curl -X 'POST' \
'https://{orgID}.enterprise-sandbox.waltid.dev/v1/{target}/client-attester-api/attest' \
-H 'accept: application/json' \
-H 'Authorization: Bearer {yourToken}' \
-H 'Content-Type: application/json' \
-d '{
"instancePublicKeyJwk": {
"kty": "EC",
"crv": "P-256",
"x": "WKn-ZIGevcwGIyyrzFoZNBdaq9_TsqzGl96oc0CWuis",
"y": "y77t-RvAHRKTsSGdIYUfweuOvwrvDD-Q3Hv5J0fSKbE"
}
}'
Body Parameters
- instancePublicKeyJwk: Object (required) - The instance public key. Any other field you send overrides the stored value.
Example Response 200 OK
{
"clientAttestationJwt": "eyJ...",
"expiresAt": 1790682000
}
The attestation's sub is the stored clientId, and it is valid for the stored expirationSeconds.
Response Codes
200- Attestation issued.400- The merged request is invalid, for example when neither the default nor the call providesclientId.401/403- Authentication or authorization failure.
Good to Know
clientIdis required. Store it, or send it on every call.- Defaults are not guardrails. A caller can send their own
clientIdorexpirationSeconds. - Explicit values win. A call with
"expirationSeconds": 60gets a 60-second attestation.
Read or Remove a Default
- List all stored defaults:
GET /v1/{target}/client-attester-api/default-requests(needsview-default-requests). - Read one:
GET …/default-requests/attest-client. Returns404if none is stored. - Remove one:
DELETE …/default-requests/attest-client. Returns204, also when nothing was stored.
Full details and permissions: Default Requests.
