TransactionType
Represents a transaction data type used for dynamic linking and transaction authorization in digital credential presentations.
Dynamic linking cryptographically binds a presentation to a specific transaction context (such as payment amount, currency, payee, or nonce) and optional user input (such as tip amount), ensuring the credential holder explicitly authorizes the transaction and protecting against relay, replay, and man-in-the-middle attacks.
Supported Protocols and Credential Formats
Transaction processing supports both major presentment protocols and credential formats across four distinct combinations:
ISO/IEC 18013-5 with ISO mdoc (
mso_mdoc): The verifier sends transaction data inside therequestInfo.transactionDatamap of an ISO 18013-5DeviceRequest. The wallet returns transaction response elements (e.g.amount,currency, andtipAmount) nested inside a CBOR map under the transaction identifier within the standard namespace (ISO_18013_TRANSACTION_DATA_NAMESPACE) inDeviceSigned.nameSpaces, bound to the request viadocRequestId.ISO/IEC 18013-5 with SD-JWT VC (
dc+sd-jwt): The verifier requests an SD-JWT VC within an ISO 18013-5DeviceRequest. The wallet generates a Key Binding JWT (KB-JWT) where transaction processing response claims are placed under kbJwtResponseClaimName (along withdoc_request_id).OpenID4VP with SD-JWT VC (
dc+sd-jwt): The verifier suppliestransaction_datain the OpenID4VP authorization request. The wallet hashes the transaction payload and insertstransaction_data_hashes_algandtransaction_data_hashes(along with user input claims) directly into the SD-JWT KB-JWT payload.OpenID4VP with ISO mdoc (
mso_mdoc): The verifier suppliestransaction_datain the OpenID4VP authorization request. The wallet places transaction evidence directly inDeviceSigned.nameSpacesunder openId4VpMdocResponseNamespace (defaulting to identifier), returning top-level data elements for the computed hash (transactionDataHash), hash algorithm (transactionDataHashAlg), and user input (tipAmount).
Lifecycle & Verification
All transaction types expected to be processed or rejected must be registered in a DocumentTypeRepository.
Applicability (isApplicable): Validates that candidate credentials authorize the device key to sign under the protocol's designated namespace (ISO_18013_TRANSACTION_DATA_NAMESPACE for ISO 18013-5, or openId4VpMdocResponseNamespace for OpenID4VP) in the Mobile Security Object (MSO).
Generation (generateMdocResponseElements, generateSdJwtResponseClaims): Invoked during wallet presentment to populate device-signed elements or KB-JWT claims based on the transaction payload and optional TransactionUserInput.
Verification (verifyMdocResponse, verifySdJwtResponse): Invoked on the verifier side during document authentication to validate that returned amounts, currencies, user inputs, and transaction hashes match the requested transaction.
Parameters
type of the transaction-specific payload data.
human-readable transaction name.
unique transaction type identifier, corresponds to the type property in transaction data in OpenID4VP; all TransactionType objects must have distinct identifiers.
if transaction processing results in any data, it will be inserted in key binding JWT using this claim name; all TransactionType objects must have distinct values.
transaction type to use in transactionData map in requestInfo map in ISO/IEC 18013-5 document request to represent this transaction data; all TransactionType objects must have distinct values.
namespace to use in deviceSigned namespace map in OpenID4VP response; defaults to identifier.
Constructors
Properties
Functions
Generates device-signed data elements for an Mdoc credential.
Generates Key Binding JWT claims for an SD-JWT credential.
Returns the DeviceSigned namespace to use for the given presentment protocol.
Determines if this transaction is applicable to the given credential.
Parses transaction data serialized for use in ISO/IEC 18013-5 presentment.
Parses transaction data serialized for use in ISO/IEC 18013 protocols.
Parses transaction data serialized for use in OpenID4VP protocol.
Parses transaction data serialized for use in OpenID4VP protocol.
Serializes transaction data for use in ISO/IEC 18013 protocols.
Verifies transaction response returned in an Mdoc presentation.
Verifies transaction response returned in an SD-JWT presentation.