---
id: ts12-payment-authorisation
title: "TS12: Payment Authorisation"
hide_title: false
sidebar_label: Payment Authorisation
description: TS12 SCA workflow for payment authorisation using a Payment Card or Payment Account credential, including transaction data with payee details, amount, and currency.
keywords: [TS12, SCA, payment confirmation, payment card, payment account, transaction data, OpenID4VP, EUDI Wallet, verifiable credentials]
slug: /ts12-payment-authorisation/
last_update:
  date: 2026-08-20
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```


import { ApiKeyManager } from "@site/src/components/ApiKeyManager";
import DcqlStepTemplate from "@site/src/components/DCQL/DcqlStepTemplate";
import {
  TS12_ATTESTATION_TYPE_OPTIONS,
  TS12_PAYMENT_ACCOUNT_CREDENTIAL_DEFINITION,
  TS12_PAYMENT_ACCOUNT_ISSUE_REQUEST,
  TS12_PAYMENT_AUTHORISATION_PRESENTATION_ACCOUNT,
  TS12_PAYMENT_AUTHORISATION_PRESENTATION_CARD,
  TS12_PAYMENT_CARD_CREDENTIAL_DEFINITION,
  TS12_PAYMENT_CARD_ISSUE_REQUEST,
  withAttestationJson,
} from "@site/src/data/ts12ScaPayloads";

TS12 SCA payment authorisation enables a relying party to authorise a payment by requesting a **Payment Card** or **Payment Account** credential with transaction data that captures the payee details, amount, and currency.

## Step 1: Get the API Key (Issuer Admin)

To obtain your API key, please contact [support@igrant.io](mailto:support@igrant.io?subject=Request%20API%20Key). Once you have received your API key, enter it in the field below and click the **Set API Key** button to save it for future use.

<ApiKeyManager />

## Step 2: Create Credential Definition (Issuer Admin)

To create a credential definition, run the interactive block below using the **Run** button. Alternatively, you can manually copy the JSON and use it in the body of the API available [here](/docs/openid4vc-api/config-create-digital-wallet-open-id-credential-definition).

From the API response, the `credentialDefinitionId` and `id` value from the `credentialDefinitions` array are autofilled in Step 3 automatically (and updated whenever Step 2 is re-run).

Use the **Attestation type** dropdown to choose **Payment Card** or **Payment Account**. The same selection is applied to credential issuance (Step 3) and the presentation definition (Step 4).

<DcqlStepTemplate
  jsonOptionLabel="Attestation type"
  jsonOptionEventName="setTs12PaymentAttestationType"
  jsonOptions={withAttestationJson(TS12_ATTESTATION_TYPE_OPTIONS.paymentCardFirst, {
    payment_card: TS12_PAYMENT_CARD_CREDENTIAL_DEFINITION,
    payment_account: TS12_PAYMENT_ACCOUNT_CREDENTIAL_DEFINITION,
  })}
  endpointPath="/v2/config/digital-wallet/openid/sdjwt/credential-definition"
  method="POST"
  extractJsonResponse={(result) => result}
  emitCredentialDefinitionIdsEvent="ts12PaymentAuthorisation:credentialDefinitionCreated"
/>

## Step 3: Issue and Receive Credential (Issuer/Holder)

When you run Step 2 on this page, the `credentialDefinitionId` and `credentials[].id` fields below are autofilled automatically (and updated whenever Step 2 is re-run). If you are executing the APIs yourself, replace `<credentialDefinitionId>` and `<id>` with the values obtained from Step 2. The holder of the wallet submits a request for the issuance of a credential by executing the JSON code block below using the **Run** button in `InTime` issuance mode. Alternatively, you may use the API available [here](/docs/openid4vc-api/config-digital-wallet-open-id-issue-credential).

After receiving the response, you can toggle the switch to dynamically generate a QR code. The EUDI Wallet/Holder can then accept the credential offer using the [Data Wallet](https://www.igrant.io/datawallet.html) (or any other EU Digital Identity Wallet) by either scanning the QR code or by directly accessing the credential offer on their mobile device (e.g. via a browser).

<DcqlStepTemplate
  jsonOptionLabel="Attestation type"
  jsonOptionEventName="setTs12PaymentAttestationType"
  jsonOptions={withAttestationJson(TS12_ATTESTATION_TYPE_OPTIONS.paymentCardFirst, {
    payment_card: TS12_PAYMENT_CARD_ISSUE_REQUEST,
    payment_account: TS12_PAYMENT_ACCOUNT_ISSUE_REQUEST,
  })}
  endpointPath="/v2/config/digital-wallet/openid/sdjwt/credential/issue"
  method="POST"
  extractJsonResponse={(result) => result}
  extractQrValue={(result) => result?.credentialHistory?.credentialOffer}
  listenCredentialDefinitionIdsEvent="ts12PaymentAuthorisation:credentialDefinitionCreated"
/>

To receive and accept the credential via API. First, use the `credentialOffer` to call the [Receive Credential API](https://docs.igrant.io/docs/openid4vc-api/config-receive-digital-wallet-open-id-credential/). Once you have the response, copy the `credentialId` and provide it at [Accept Credential API](https://docs.igrant.io/docs/openid4vc-api/config-accept-digital-wallet-open-id-credential/) to accept the credential.

## Step 4: Create Presentation Definition (Verifier Admin)

To create a presentation definition for requesting proof, you can run the code block below using the **Run** button. Alternatively, you can manually copy the code block and use it in the body of the API request provided [here](/docs/openid4vc-api/config-digital-wallet-open-id-presentation-definition).

Once a presentation definition has been created, the `presentationDefinitionId` is autofilled in Step 5 automatically (and updated whenever Step 4 is re-run). You can also reuse the same `presentationDefinitionId` to verify multiple credentials.

Use the **Attestation type** dropdown to request proof of a **Payment Card** or **Payment Account** credential. Choose the same type you issued in Steps 2 and 3.

<DcqlStepTemplate
  jsonOptionLabel="Attestation type"
  jsonOptionEventName="setTs12PaymentAttestationType"
  jsonOptions={withAttestationJson(TS12_ATTESTATION_TYPE_OPTIONS.paymentCardFirst, {
    payment_card: TS12_PAYMENT_AUTHORISATION_PRESENTATION_CARD,
    payment_account: TS12_PAYMENT_AUTHORISATION_PRESENTATION_ACCOUNT,
  })}
  endpointPath="/v2/config/digital-wallet/openid/sdjwt/presentation-definition"
  method="POST"
  extractJsonResponse={(result) => result}
  emitPresentationDefinitionIdEvent="ts12PaymentAuthorisation:presentationDefinitionCreated"
/>

## Step 5: Create Verification Request (Verifier/Relying Party)

When you run Step 4 on this page, the `presentationDefinitionId` field below is autofilled automatically (and updated whenever Step 4 is re-run). If you are executing the APIs yourself, replace `<presentationDefinitionId>` with the ID obtained in Step 4. To create the verification request, execute the code block below using the **Run** button. Alternatively, you can manually copy the JSON and use it in the body of the API available [here](/docs/openid4vc-api/config-create-digital-wallet-open-id-verification-request-v-3). This step includes `transactionData` in the verification request payload, which is specific to TS12 SCA workflows. The `transactionData.payload` contains the transaction details that are dynamically linked to the user's authentication.

After receiving the response, toggle the button provided to dynamically generate a QR code. The EUDI Wallet/Holder can then accept the verification request using the Data Wallet (or any other EU Digital Identity Wallet) by either scanning the QR code or directly accessing the verification request on their mobile device, such as via a browser.

<DcqlStepTemplate
  initialJsonData={{
    requestByReference: true,
    transactionData: {
      payload: {
        transaction_id: "FERRY-PAY-1747137600000",
        date_time: "2026-05-05T12:00:00.000Z",
        payee: {
          name: "Fast Ferries",
          id: "FASTFERRIES-SE-001",
          logo: "https://www.fastferries.com/assets/logo.png",
          website: "https://www.fastferries.com",
        },
        execution_date: "2026-05-05T12:00:00.000Z",
        currency: "EUR",
        amount: 89.50,
        amount_estimated: false,
        amount_earmarked: false,
        sct_inst: true,
      },
    },
    presentationDefinitionId: "<presentationDefinitionId>",
  }}
  endpointPath="/v3/config/digital-wallet/openid/sdjwt/verification/send"
  method="POST"
  extractJsonResponse={(result) => result}
  extractQrValue={(result) => result?.verificationHistory?.vpTokenQrCode}
  listenPresentationDefinitionIdEvent="ts12PaymentAuthorisation:presentationDefinitionCreated"
/>

Users can copy the `presentationExchangeId` from the JSON response to track verification history. The Verifier (Relying Party) receives the requested credentials and can verify it. They may read the received credential by executing the [Read Verification History API](/docs/openid4vc-api/config-read-digital-wallet-open-id-verification-history-v-3).
