agentsclimarketplace

Igrantio verifier frontend

Skill L3-iGrant/skills/ows/igrantio-verifier-frontend

Build the browser UI for an OpenID4VP + DCQL credential VERIFIER / relying party against the iGrant.io Organisation Wallet Suite. Send a presentation request through your tenant backend proxy, render the QR (cross-device) or invoke the same-device Digital Credentials API to reach the EUDI Wallet (EUDIW) or European Business Wallet (EUBW), and read the disclosed claims + verified decision live over SSE. Composes igrantio-frontend-client; talks to igrantio-verifier-backend.From its SKILL.md

Install
npx -y skills add L3-iGrant/skills --skill igrantio-verifier-frontend

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its file declares

Copied from the file, not written here

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

5.0 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

iGrant.io verifier frontend (OpenID4VP + DCQL)

When to use

Build the relying-party UI: request a verifiable presentation, let the user scan a QR (or use the same-device wallet), and show the disclosed claims and the verified decision the instant the wallet responds. Depends on igrantio-frontend-client (vendored at src/lib/ows/) and an igrantio-verifier-backend deployment. Issuer UI is a separate skill (igrantio-issuer-frontend).

Before you build: run the integrator intake in igrantio-ows-overview - environment, API key, tenancy, backend host, webhooks, frontend - one question at a time, a recommended default with each.

What it provides

  • useVerification({ proxyBaseUrl, webhookBaseUrl }){ status, qrUri, presentationExchangeId, result, error, requestPresentation, reset }.
    • requestPresentation(payload) - send a DCQL request; returns the full verificationHistory (so you can also drive same-device DC API).
    • result: { verified, claims, presentations } once the wallet responds.
    • status: idle → waiting → verified | rejected (or error).
  • dcApi.ts - same-device Digital Credentials API helpers (supportsDcApi, invokeWallet, buildReceivePayload).
  • VerifierFlow - a minimal end-to-end demo component.

Flow (what happens)

  1. POST …/verification/send with presentationDefinitionId → read verificationHistory.presentationExchangeId (SSE key) and verificationHistory.vpTokenQrCode (QR URI). Optionally include transactionData (SCA payment, e-mandate, login/risk, account access, or QES signing - typed as TransactionData in lib/ows/types.ts; shapes in igrantio-ows-overview api-reference §2.1) so the wallet displays and signs over the transaction details.
  2. Open SSE on the exchange id; render the QR / same-device button. For the full QR panel (optional centre logo, green tick on scan, refresh, open-in-wallet button) use igrantio-qr-code - it asks the integrator about the logo and tick options.
  3. SSE data.presentation: once vpTokenResponse.length > 0, read presentation[0] (disclosed claims) and verified (decision). Accept only when verified === true (plus your trust rules).

Steps

  1. Vendor igrantio-frontend-client/references/lib/ows into src/lib/ows/.
  2. Copy ./references/features/verifier into src/features/verifier/.
  3. npm i qrcode @types/qrcode.
  4. Wire it up:
    <VerifierFlow
      proxyBaseUrl="https://host/ows/acme"
      webhookBaseUrl="https://host/webhook"
      presentationDefinitionId="<pd-id>"
    />
    

Same-device (optional)

If requestPresentation returns a verificationHistory.dcApiRequest, call invokeWallet(dcApiRequest) from dcApi.ts, then post the result back to OWS via the proxy (buildReceivePayload) on an allow-listed receive path. The SSE stream still delivers the final verified result, so the render path is unchanged. Platform-specific end-to-end recipes: igrantio-dcapi-android (OpenID4VP) and igrantio-dcapi-ios (ISO 18013-7 Annex C, signed).

Clean-code notes

  • No @igrant/* SDK; OWS specifics live in the client, flow logic in the hook, DC-API concerns isolated in dcApi.ts.
  • Read the decision from verified and claims from presentation[0] - the only fields the UI needs.

Validation / done criteria

  • Presenting a valid credential drives status to verified with the disclosed claims shown; a tampered/absent one shows rejected.
  • No OWS API key is present anywhere in the browser bundle.

Documentation & workflows

When anything is unclear, consult the iGrant.io documentation before guessing:

What ships with it: 16 files

31.4 KB alongside SKILL.md, 12 of them executable

Keep looking

Skills are one crate of 326,506. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.