How to fill trusted registries

To insert transactions into the underlying blockchain, a Legal Entity must have a valid Verifiable Credential (VC) for the specified purpose and request an access token with the appropriate scope.

Scope definitions

To help understand the context and requirements for each scope used in the process, the following table provides a detailed explanation of the scopes.

ScopeRequired Verifiable CredentialGranted Access
didr_inviteVerifiableAuthorisationToOnboardCan register DID into DID Registry
tir_inviteVerifiableAuthorisationForTrustChain or
VerifiableAccreditationToAttest or
Can register VC into Trusted Issuers Registry
No credentials are required, but the client must be a Trusted Issuer.Can fully manipulate DID Registry and Trusted Issuers Registry

Sequence diagram

Step-by-step guide

1. Query presentation definition requirements

To start, query the Presentation definitions endpoint to get the requirements for the vp_token.

This endpoint can list all possible definitions or select one with the desired scope. Use the query parameter scope with a space-separated list of values.

Presentation definition query example

id: 'didr_invite_presentation',
input_descriptors: [
id: 'didr_invite_credential',
name: 'Accreditation to write to the DID Registry',
purpose: 'Please present a valid VerifiableAuthorisationToOnboard issued by Root TAO or TAO',
format: { jwt_vc: { alg: [ 'ES256' ] } },
constraints: {
fields: [
path: [ '$.vc.type' ],
filter: {
type: 'array',
contains: { const: 'VerifiableAuthorisationToOnboard' }
format: { jwt_vc: { alg: [ 'ES256' ] }, jwt_vp: { alg: [ 'ES256' ] } }

2. Request token

After handling the Presentation Definition requirements, form a Verifiable Presentation (VP) Token with Presentation Submission and send it to the Token Endpoint with grant_type=vp_token and the requested scopes. The response will include an Access Token, which can be used with EBSI Services.

Token request example


JWT Header:
typ: 'JWT',
alg: 'ES256',
kid: 'did:ebsi:zdPj1GPXjfERXxXPE1YTYdJ#7j3TpaNdPNTOzOtouOOknlOLQk3JP-ykTfraWtY3GME'
JWT Payload:
iss: 'did:ebsi:zdPj1GPXjfERXxXPE1YTYdJ',
aud: '',
sub: 'did:ebsi:zdPj1GPXjfERXxXPE1YTYdJ',
iat: 1589699260,
nbf: 1589699260,
exp: 1589699260,
nonce: 'xjfOUNf59asfn23fNk123kflsD',
jti: 'urn:uuid:0706061a-e2ca-4614-9de7-9c1451935f02',
vp: {
'@context': [ '' ],
id: 'urn:uuid:0706061a-e2ca-4614-9de7-9c1451935f02',
type: [ 'VerifiablePresentation' ],
holder: 'did:ebsi:zdPj1GPXjfERXxXPE1YTYdJ',
verifiableCredential: [

3. Filling the Trusted Registry

After obtaining the Access Token in Step 2, the next step involves interacting with the Trusted Registry using its JSON RPC API. This includes selecting and utilising the appropriate method based on specific requirements. The process generally involves building a transaction, receiving the Ethereum transaction for signing, and then submitting the signed transaction back to the Trusted Registry.

The available methods and their required parameters are detailed in the TIR JSON-RPC API documentation.