Credential Workbench · T545

SD-JWT Disclosure Workbench

Issue a Selective Disclosure JWT (RFC 9901) with per-claim disclosure toggles, or paste any SD-JWT to build a redacted presentation with an optional holder-binding KB-JWT. The what-the-verifier-sees panel shows exactly the disclosed subset a relying party would receive.

SD-JWT · RFC 9901 KB-JWT holder binding §27.6 Evidence Bundle Zero PII Client-Side
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
⚠ A verified SD-JWT proves the disclosed claims were issued and are unaltered, and (with a valid KB-JWT) that the presenter holds the bound key. It is not, by itself, identity assurance: keys are self-asserted unless separately anchored. See the credential workbench guide.
Claims & Disclosure Toggles
Claim keyValueSelectively disclosable
Issued SD-JWT (issuer copy, all disclosures attached)
Always-disclosed payload / disclosures
Selectively disclosable
Paste SD-JWT
Presentation (redacted SD-JWT + optional KB-JWT)
What the verifier sees
OCG Receipt of the Presentation Activity
SPEC §27.6 Evidence Bundle → SD-JWT

Paste a haEvidenceBundle JSON, exported from the §27.6 step of the OCG Verify page, and issue it as a Selective Disclosure JWT using the same engine as the Issue tab. Always-disclosed: subject_hash, verification_result, kernel_version, policy_version, timestamps, submission_receipt. Selectively disclosable: reviewers, approvers, annotations, exception_rationale, input_hashes, matching chaingraph/kernels/_haevidence.mjs.

Issued Evidence SD-JWT
Always-disclosed payload / disclosures
Selectively disclosable
Sent to the Present tab. Switch there to build a redacted presentation for a specific examiner.