Igrantio verifier frontend
Build the browser UI for an OpenID4VP + DCQL credential VERIFIER / relying party against the iGrant.io Organisation Wallet Suite. Send a presentation request through your tenant backend proxy, render the QR (cross-device) or invoke the same-device Digital Credentials API to reach the EUDI Wallet (EUDIW) or European Business Wallet (EUBW), and read the disclosed claims + verified decision live over SSE. Composes igrantio-frontend-client; talks to igrantio-verifier-backend.From its SKILL.md
npx -y skills add L3-iGrant/skills --skill igrantio-verifier-frontendAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its file declares
Copied from the file, not written here
The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
5.0 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it
iGrant.io verifier frontend (OpenID4VP + DCQL)
When to use
Build the relying-party UI: request a verifiable presentation, let the user scan
a QR (or use the same-device wallet), and show the disclosed claims and the
verified decision the instant the wallet responds. Depends on
igrantio-frontend-client (vendored at src/lib/ows/) and an
igrantio-verifier-backend deployment. Issuer UI is a separate skill
(igrantio-issuer-frontend).
Before you build: run the integrator intake in igrantio-ows-overview - environment, API key, tenancy, backend host, webhooks, frontend - one question at a time, a recommended default with each.
What it provides
useVerification({ proxyBaseUrl, webhookBaseUrl })→{ status, qrUri, presentationExchangeId, result, error, requestPresentation, reset }.requestPresentation(payload)- send a DCQL request; returns the fullverificationHistory(so you can also drive same-device DC API).result:{ verified, claims, presentations }once the wallet responds.status:idle → waiting → verified | rejected(orerror).
dcApi.ts- same-device Digital Credentials API helpers (supportsDcApi,invokeWallet,buildReceivePayload).VerifierFlow- a minimal end-to-end demo component.
Flow (what happens)
POST …/verification/sendwithpresentationDefinitionId→ readverificationHistory.presentationExchangeId(SSE key) andverificationHistory.vpTokenQrCode(QR URI). Optionally includetransactionData(SCA payment, e-mandate, login/risk, account access, or QES signing - typed asTransactionDatainlib/ows/types.ts; shapes inigrantio-ows-overviewapi-reference §2.1) so the wallet displays and signs over the transaction details.- Open SSE on the exchange id; render the QR / same-device button. For the
full QR panel (optional centre logo, green tick on scan, refresh,
open-in-wallet button) use
igrantio-qr-code- it asks the integrator about the logo and tick options. - SSE
data.presentation: oncevpTokenResponse.length > 0, readpresentation[0](disclosed claims) andverified(decision). Accept only whenverified === true(plus your trust rules).
Steps
- Vendor
igrantio-frontend-client/references/lib/owsintosrc/lib/ows/. - Copy
./references/features/verifierintosrc/features/verifier/. npm i qrcode @types/qrcode.- Wire it up:
<VerifierFlow proxyBaseUrl="https://host/ows/acme" webhookBaseUrl="https://host/webhook" presentationDefinitionId="<pd-id>" />
Same-device (optional)
If requestPresentation returns a verificationHistory.dcApiRequest, call
invokeWallet(dcApiRequest) from dcApi.ts, then post the result back to OWS via
the proxy (buildReceivePayload) on an allow-listed receive path. The SSE stream
still delivers the final verified result, so the render path is unchanged.
Platform-specific end-to-end recipes: igrantio-dcapi-android (OpenID4VP) and
igrantio-dcapi-ios (ISO 18013-7 Annex C, signed).
Clean-code notes
- No
@igrant/*SDK; OWS specifics live in the client, flow logic in the hook, DC-API concerns isolated indcApi.ts. - Read the decision from
verifiedand claims frompresentation[0]- the only fields the UI needs.
Validation / done criteria
- Presenting a valid credential drives
statustoverifiedwith the disclosed claims shown; a tampered/absent one showsrejected. - No OWS API key is present anywhere in the browser bundle.
Documentation & workflows
When anything is unclear, consult the iGrant.io documentation before guessing:
- iGrant.io developer APIs (index): https://docs.igrant.io/docs/developer-apis
- Getting started: https://docs.igrant.io/docs/get-started/
- OpenID4VC API (issuer / verifier / webhook): https://docs.igrant.io/docs/category/openid4vc-api/issuer
- Workflow: send and verify credentials (OID4VP): https://docs.igrant.io/docs/openID4vc-send-verify-credentials/
What ships with it: 16 files
31.4 KB alongside SKILL.md, 12 of them executable
references/
- features/verifier/dcApi.tsruns3.6 KB
- features/verifier/useVerification.tsruns3.5 KB
- features/verifier/VerifierFlow.tsx1.7 KB
- lib/ows/index.tsruns344 B
- lib/ows/owsClient.tsruns4.1 KB
- lib/ows/react/index.tsruns375 B
- lib/ows/react/QrCode.tsx1.3 KB
- lib/ows/react/useCredentialHistory.tsruns755 B
- lib/ows/react/useOwsClient.tsruns382 B
- lib/ows/react/usePolledResource.tsruns1.6 KB
- lib/ows/react/useSSE.tsruns1.2 KB
- lib/ows/react/useVerificationHistory.tsruns816 B
- lib/ows/sseClient.tsruns2.6 KB
- lib/ows/types.tsruns8.4 KB
- package.json462 B
- tsconfig.json312 B