check

abstract suspend fun check(revocationStatus: RevocationStatus, issuerCert: X509Cert? = null, onlyTrusted: Boolean = true, atTime: Instant = Clock.System.now(), bypassCache: Boolean = false, preferJwt: Boolean = false): RevocationCheckResult

Checks the revocation state for a given non-null RevocationStatus payload.

This method never throws exceptions for non-cancellation errors (such as network, HTTP, timeout, parsing, or signature verification failures). Instead, those errors are caught internally and returned as a RevocationCheckResult with state RevocationCheckState.UNKNOWN and the underlying exception in RevocationCheckResult.error. Standard coroutine CancellationExceptions are preserved and rethrown.

Return

RevocationCheckResult indicating whether the credential is valid, revoked, suspended, or unknown.

Parameters

revocationStatus

The revocation status object (StatusList or IdentifierList) extracted from the presentation.

issuerCert

The top-level certificate chain of the issuer / document signer (e.g. AICA certificate for ISO mdoc credentials); it is used for signature verification unless it is included in the revocationStatus (uncommon); if this is null, and certificate in the revocationStatus is null, onlyTrusted should be false, or the check will always return RevocationCheckState.UNKNOWN in RevocationCheckResult.state

onlyTrusted

Only accept trusted revocation data (valid and correctly signed)

atTime

The point in time at which to evaluate revocation status validity. Defaults to current system time.

bypassCache

If true, forces downloading a fresh status/identifier list payload from the network rather than using cached data.

preferJwt

Prefer status list data in JWT format, rather than more compact CWT; mostly exposed for testing