Skip to main content

Add credentials

Open Add Credentials to receive a credential through OpenID4VCI. Vault supports two entry points: choosing a registered credential from the catalog or importing a one-time offer supplied by an issuer.

UbID Vault Add Credentials catalog

An internet connection is required to validate issuers, resolve offers, and complete issuance.

Choose from the catalog​

Use the search field or select an entry under Recent or All. Always read the credential name and issuer shown on the card.

Vault asks for confirmation before leaving the application:

  • UbID Credential Basic SSI redirects to UbID Authorization Server.

    Basic SSI credential redirect confirmation

  • UbID Verifiable Education Credential redirects to UbID Credential Issuer.

    Education credential redirect confirmation

  • UbID Portable Biometric URCode Credential redirects to UbID Credential Issuer.

    Portable biometric credential redirect confirmation

Select Cancel if the name, issuer, or description is unexpected. Select Continue only when you recognize the destination.

The Authorization Server shows the credential that will be returned to Vault. Select the credential card, use Show Details when available, and review the Client and Expiration values before authorizing.

For the Basic SSI flow, the selected digital identity credential is shown on the consent page.

Authorization consent for the UbID Basic SSI credential

Select Send Credentials to UbID Vault only after confirming that the client is the expected Vault domain. The displayed expiration belongs to the authorization or credential flow; it is not the Vault session duration.

Education and portable biometric credentials​

These two credentials use delegated issuance and require exactly one prepared, authorized pending item for the same UbID identity.

Authorization consent for an education credential

Authorization consent for a portable biometric credential

If the card says No hay credenciales autorizadas pendientes or an equivalent message, do not continue: issuance is not ready. Return to Issuer and complete the prerequisite workflow:

  • for an education credential, upload and review the corresponding degree or diploma evidence;
  • for a portable biometric credential, complete FaceTec enrollment, national-identity verification, and preparation of the portable biometric credential.

Then start the credential again from Vault. The delegated flow verifies that the Vault account, public-profile subject, pending item, credential type, and holder key all match. It does not guess when zero or multiple pending items are available.

Import an OpenID4VCI offer​

Use Paste offer for a complete openid-credential-offer://… URI, or Scan QR to read the issuer's offer with the camera.

  1. Paste or scan the offer supplied directly by the issuer.
  2. Select Review offer.
  3. Confirm the issuer, host, credential type, and authorization method.
  4. If a transaction code is required, obtain it through the issuer's approved channel.
  5. Select Accept credential.

The pasted offer is kept only in memory and cleared from the form after validation. Vault signs the holder proof internally; the private key does not leave the Vault. One-time offers can expire or be consumed, so request a new offer if validation or issuance fails.

Confirm receipt​

After a successful flow, return to Credentials and verify that the new card appears with the expected issuer, subject, and validity period. If it is not visible, refresh once and check that you returned to the same Vault account before repeating issuance.