Ga naar inhoud

List credentials

GET
/api/v1/credentials
curl --request GET \
--url https://example.com/api/v1/credentials \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E

The verifiable credentials in the participant’s wallet, such as the membership credential of the authority.

OK.

Media typeapplication/json

A page of a list. next_cursor is null on the last page.

object
items
required
Array<object>

A credential in the wallet (crate::dcp::Dcp::credentials).

object
id
required
string
type
required

The credential types, e.g. VerifiableCredential, MembershipCredential.

Array<string>
issuer
required

The DID of the issuer.

string
issued_at
string | null format: date-time
expires_at
string | null format: date-time
status
required

valid, expired, revoked, …

string
claims
required

The credential subject.

object
jwt
required

The credential as a JWT.

string
from_authority
required

Issued by the authority of the dataspace.

boolean
next_cursor

Pass as cursor for the next page.

string | null

Example generated

{
"items": [
{
"id": "example",
"type": [
"example"
],
"issuer": "example",
"issued_at": "2026-04-15T12:00:00Z",
"expires_at": "2026-04-15T12:00:00Z",
"status": "example",
"claims": {},
"jwt": "example",
"from_authority": true
}
],
"next_cursor": "example"
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}