List credentials
const url = 'https://example.com/api/v1/credentials';const options = { method: 'GET', headers: {cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/credentials \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3EThe verifiable credentials in the participant’s wallet, such as the membership credential of the authority.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK.
A page of a list. next_cursor is null on the last page.
object
A credential in the wallet (crate::dcp::Dcp::credentials).
object
The credential types, e.g. VerifiableCredential, MembershipCredential.
The DID of the issuer.
valid, expired, revoked, …
The credential subject.
object
The credential as a JWT.
Issued by the authority of the dataspace.
Pass as cursor for the next page.
Example generated
{ "items": [ { "id": "example", "type": [ "example" ], "issuer": "example", "issued_at": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z", "status": "example", "claims": {}, "jwt": "example", "from_authority": true } ], "next_cursor": "example"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}