TransactionType

abstract class TransactionType<PayloadT : Any>(val displayName: String, val identifier: String, val kbJwtResponseClaimName: String = identifier, val iso18013RequestInfoIdentifier: String = identifier, val openId4VpMdocResponseNamespace: String = identifier)

Represents a transaction data type used for dynamic linking and transaction authorization in digital credential presentations.

Dynamic linking cryptographically binds a presentation to a specific transaction context (such as payment amount, currency, payee, or nonce) and optional user input (such as tip amount), ensuring the credential holder explicitly authorizes the transaction and protecting against relay, replay, and man-in-the-middle attacks.

Supported Protocols and Credential Formats

Transaction processing supports both major presentment protocols and credential formats across four distinct combinations:

  1. ISO/IEC 18013-5 with ISO mdoc (mso_mdoc): The verifier sends transaction data inside the requestInfo.transactionData map of an ISO 18013-5 DeviceRequest. The wallet returns transaction response elements (e.g. amount, currency, and tipAmount) nested inside a CBOR map under the transaction identifier within the standard namespace (ISO_18013_TRANSACTION_DATA_NAMESPACE) in DeviceSigned.nameSpaces, bound to the request via docRequestId.

  2. ISO/IEC 18013-5 with SD-JWT VC (dc+sd-jwt): The verifier requests an SD-JWT VC within an ISO 18013-5 DeviceRequest. The wallet generates a Key Binding JWT (KB-JWT) where transaction processing response claims are placed under kbJwtResponseClaimName (along with doc_request_id).

  3. OpenID4VP with SD-JWT VC (dc+sd-jwt): The verifier supplies transaction_data in the OpenID4VP authorization request. The wallet hashes the transaction payload and inserts transaction_data_hashes_alg and transaction_data_hashes (along with user input claims) directly into the SD-JWT KB-JWT payload.

  4. OpenID4VP with ISO mdoc (mso_mdoc): The verifier supplies transaction_data in the OpenID4VP authorization request. The wallet places transaction evidence directly in DeviceSigned.nameSpaces under openId4VpMdocResponseNamespace (defaulting to identifier), returning top-level data elements for the computed hash (transactionDataHash), hash algorithm (transactionDataHashAlg), and user input (tipAmount).

Lifecycle & Verification

All transaction types expected to be processed or rejected must be registered in a DocumentTypeRepository.

Parameters

PayloadT

type of the transaction-specific payload data.

displayName

human-readable transaction name.

identifier

unique transaction type identifier, corresponds to the type property in transaction data in OpenID4VP; all TransactionType objects must have distinct identifiers.

kbJwtResponseClaimName

if transaction processing results in any data, it will be inserted in key binding JWT using this claim name; all TransactionType objects must have distinct values.

iso18013RequestInfoIdentifier

transaction type to use in transactionData map in requestInfo map in ISO/IEC 18013-5 document request to represent this transaction data; all TransactionType objects must have distinct values.

openId4VpMdocResponseNamespace

namespace to use in deviceSigned namespace map in OpenID4VP response; defaults to identifier.

Constructors

Link copied to clipboard
constructor(displayName: String, identifier: String, kbJwtResponseClaimName: String = identifier, iso18013RequestInfoIdentifier: String = identifier, openId4VpMdocResponseNamespace: String = identifier)

Types

Link copied to clipboard
object Companion

Properties

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Functions

Link copied to clipboard
open suspend fun generateMdocResponseElements(transactionData: TransactionData<PayloadT>, credential: Credential, userInput: TransactionUserInput?, docRequestId: Int? = null): Map<String, DataItem>

Generates device-signed data elements for an Mdoc credential.

Link copied to clipboard
open suspend fun generateSdJwtResponseClaims(transactionData: TransactionData<PayloadT>, credential: Credential, userInput: TransactionUserInput?, docRequestId: Int? = null): Map<String, JsonElement>

Generates Key Binding JWT claims for an SD-JWT credential.

Link copied to clipboard

Returns the DeviceSigned namespace to use for the given presentment protocol.

Link copied to clipboard
open suspend fun isApplicable(transactionData: TransactionData<PayloadT>, credential: Credential): Boolean

Determines if this transaction is applicable to the given credential.

Link copied to clipboard
open fun parseCbor(serialized: DataItem): TransactionData<PayloadT>

Parses transaction data serialized for use in ISO/IEC 18013-5 presentment.

Link copied to clipboard

Parses transaction data serialized for use in ISO/IEC 18013 protocols.

Link copied to clipboard
open fun parseJson(serialized: ByteString): TransactionData<PayloadT>

Parses transaction data serialized for use in OpenID4VP protocol.

Link copied to clipboard
open fun parseOpenId4VpRequest(jsonString: String): PayloadT

Parses transaction data serialized for use in OpenID4VP protocol.

Link copied to clipboard

Serializes transaction data for use in ISO/IEC 18013 protocols.

Link copied to clipboard
open fun serializeOpenId4VpRequest(payload: PayloadT, credentialIds: List<String>, hashAlgorithms: List<Algorithm>? = null): String

Serializes transaction data for use in OpenID4VP protocol.

Link copied to clipboard
open suspend fun verifyMdocResponse(transactionData: TransactionData<PayloadT>, responseElements: Map<String, DataItem>)

Verifies transaction response returned in an Mdoc presentation.

Link copied to clipboard
open suspend fun verifySdJwtResponse(transactionData: TransactionData<PayloadT>, responseClaims: Map<String, JsonElement>)

Verifies transaction response returned in an SD-JWT presentation.