Skip to main content
This recipe gates a feature on a loyalty tier. When a user opens a members-only page, your app asks for their tier credential, checks the result, and unlocks the page only for qualifying tiers. It builds on the verification quickstart, which covers the setup this recipe reuses: the server route that returns a Partner JWT and nonce, and the backend route that verifies the presentation.

Prerequisites

  • The verification quickstart’s /api/verification-token and /api/verify-presentation routes.
  • A schema with a tier claim, and a test user who holds a credential from an issuer you accept.

Step 1: Create a program that requests the tier

  1. In the Developer Dashboard, go to Verifier → Programs and create a program.
  2. Select the schema with the tier claim and the issuers you accept.
  3. Request the tier claim, and publish the program.
  4. Copy the verification program ID.

Step 2: Request the tier when the user opens the page

If the user doesn’t hold the credential yet, pass an optional redirectUrl that points to the issuer’s claim page.

Step 3: Gate the feature on the result

Only "Compliant" results carry a verifiablePresentation. Other statuses, such as "Non-Compliant", "NotFound", "Expired", or "Revoked", have none. See the response reference for the full list.
Check the disclosed tier value on your backend when it verifies the presentation, and unlock the page only for the tiers you allow. Wrap verifyCredential in try/catch: a cancelled consent dialog or a rejected token rejects the promise instead of returning a status.
A "Compliant" result is checked in the user’s browser, and the presentation wrapper is not signed. Before granting anything of value, verify the SD-JWT inside it on your backend, including the key-binding JWT against your nonce. See Verify SD-JWT on your backend.

Next steps