Iden3 credentials are an advanced option. Contact the AIR team to enable them for your partner account before you start: Partner with us. New integrations should use SD-JWT VC, which is self-serve.
When to use Iden3
Choose Iden3 over SD-JWT when you need one of these:- Predicate proofs. Prove a condition such as
age > 18without revealing the value. - Unlinkable presentations. Each proof is randomized, so verifiers cannot link a holder’s presentations.
- On-chain verification. Check a proof through the Universal Verifier and Groth16 verifier contracts.
Set up the issuer service
Iden3 issuers use the Iden3 branch of the AIR issuer service. It exposes the samePOST /available-vc and POST /issue-vc contract as the SD-JWT service, with proofType: "BJJ_SIG_2021".
Generate the issuer seed
Your BJJ issuer DID is derived from a 32-byte seed:Configure the environment
Extract the issuer DID
Start the service. It logs the DID at startup asIssuer DID: did:air:…. You can also print it with the REPL:
Define a schema class
Create the schema in the Dashboard and record its schema ID, type, schema JSON URL, and JSON-LD context URL. Then add a class undersrc/issuer/schemas/:
src/issuer/schemas/schema-<SCHEMA_ID>.ts
src/issuer/schemas/index.ts:
src/issuer/schemas/index.ts
credentialSubject.id to the holder DID.
Issue in bulk without a user session
The Iden3 service includes a CSV runner. It resolves each email through AIRinitialize-user, issues, encrypts, and uploads:
credentialSubject.[field] cell must be a JSON-stringified value, so strings carry quotes.
[unix_timestamp_ms].csv.
Revocation and status
The Iden3 service embeds a
/credential-status URL under ISSUER_ORIGIN in each credential, so keep the origin stable. It does not support the token status list.
Issue both formats
A partner that issues SD-JWT and Iden3 credentials runs both services, each at its ownISSUER_ORIGIN. Set IDEN3_ISSUER_DID on the SD-JWT service to your BJJ issuer DID; it is then listed under alsoKnownAs in your did:web document.
Verify Iden3 credentials
Verification programs for Iden3 credentials can require a zero-knowledge proof and choose where it is checked:
For Iden3 programs,
verifiablePresentation.verifiableCredential holds W3C Verifiable Credential objects whose credentialSubject contains the disclosed claims. proof is present only when the program requires a zero-knowledge proof. It carries the Groth16 proofValue and publicSignals, plus transactionHash for on-chain programs. Programs with several ZK queries return one entry per query. See VerifiablePresentationProof in the SDK reference.
Iden3 credentials and personal data stay off-chain. Depending on the profile, only proofs, verification results, issuer state roots, or revocation commitments are recorded on Moca Chain.