Payment Account Credential (TS12) - credential schema
When to use
Use this skill when you issue or verify a Payment Account Credential (TS12). The credential states the payment account of the holder. It is one of the three SCA payment credentials in the registry, together with the payment card credential and the payment user credential.
The metadata sets isScaCredential to true. The schema supports one format:
SD-JWT VC (dc+sd-jwt).
The registry keeps this schema under
credentialSchemas/claimPathPointer/scaPaymentAccount. Version 2025.7.1 is the latest
version directory, and this skill uses it. The registry publishes the schema
in one format: dc+sd-jwt.
What the claims describe
The registry defines three claims. All three are mandatory, and all three set
limitDisclosure to true, so the holder can disclose each one on its own.
iban- the international bank account number of the account.bic- the business identifier code of the bank.currency- the currency of the account.
A verifier that only needs the bank can ask for bic alone, and the holder
keeps the iban hidden.
Claim path pointer documents
Each document below is the file that the registry holds. Copy it without a change.
SD-JWT VC (dc+sd-jwt)
| Fact | Value |
|---|---|
| Title | Payment Account Credential (TS12) |
| Format | dc+sd-jwt |
credentialType |
{baseUrl}/service/vct-metadata/payment_account |
vct to send |
{baseUrl}/service/vct-metadata/payment_account |
validationPath |
$ |
| Claim carrier in the request | claims |
The credentialType holds the placeholder {baseUrl}. Replace {baseUrl} with
the base URL of the service that publishes the VCT metadata before you send the
value in the vct field. The registry keeps the placeholder so that the same
schema works for each deployment.
{
"claims": [
{
"path": [
"iban"
],
"mandatory": true,
"limitDisclosure": true
},
{
"path": [
"bic"
],
"mandatory": true,
"limitDisclosure": true
},
{
"path": [
"currency"
],
"mandatory": true,
"limitDisclosure": true
}
]
}
How to read a claim path pointer
A claim path pointer selects one claim in the credential. Each item of the
claims array holds these fields.
pathis mandatory and holds at least one element. Read the elements from left to right. A string element selects an object key. An integer element selects one array index. Anullelement selects every element of an array, so["nationalities", null]covers each entry of thenationalitiesarray.mandatorysays whether the issuer must supply a value for the claim. The issuer reads a missingmandatoryfield astrue.limitDisclosuresays that the holder can disclose the claim on its own. Set it only inside theclaimsobject of adc+sd-jwtormso_mdocconfiguration. Thejwt_vc_jsonformat has no selective disclosure, so its documents leave the field out.
A path that names a parent object, such as ["address"], and a path that names
a child, such as ["address", "country"], can both appear. The parent pointer
lets the holder disclose the full object. The child pointers let the holder
disclose one field at a time.
For mso_mdoc, the first element of the path is the mDoc namespace, every
path holds at least two elements, and every path of one configuration uses the
same first element.
For jwt_vc_json, the first element of the path is always credentialSubject.
Use with the iGrant.io API
Create a credential definition with
POST /v2/config/digital-wallet/openid/sdjwt/credential-definition. Put the
claims array of the registry document into the configuration entry, and set
vct to the credential type with {baseUrl} replaced.
{
"label": "Issue Payment Account",
"version": "version_01",
"credentialDefinitions": [
{
"credentialFormat": "dc+sd-jwt",
"vct": "{baseUrl}/service/vct-metadata/payment_account",
"validationPath": "$",
"claims": {
"claims": [
{
"path": [
"iban"
],
"mandatory": true,
"limitDisclosure": true
},
{
"path": [
"bic"
],
"mandatory": true,
"limitDisclosure": true
}
]
}
}
]
}
The label Payment Account Credential is reserved for the platform. Pick
another label, for example Issue Payment Account.
Keep limitDisclosure as true on each claim. A payment verifier usually asks
for one field, and selective disclosure keeps the rest of the account data with
the holder.
Notes on the request.
labelmust hold at least 3 characters. The platform reserves the labelsPayment User Credential,Payment Card Credential,Payment Account Credential,PID IssuanceandPhoto ID Issuance, so pick another label.- Always send
versionwith the valueversion_01. The issuer falls back to an earlier version of the specification when you leave the field out, and you cannot change the value after you create the credential definition. - Add one entry of
credentialDefinitions[]for each format that you want to publish. You can publish more than one format from one credential definition. - Keep the
idthat the response returns for each entry. The issue operation uses that value to match the claims to a configuration. - Add
supportRevocation,revocationMethod,expirationInDays,displayand the other entry fields as your use case needs them.
Read igrantio-api-issuer for the full operation reference, the other request
fields, and the issue operation that follows.
Source is the registry
The verifiable data registry is the source of truth. If this skill and the registry file disagree, the registry wins. Fetch the source before you rely on a claim path, and report the difference so this skill can be corrected.
- Template directory: https://github.com/decentralised-dataexchange/verifiable-data-registry/tree/main/credentialSchemas/claimPathPointer/scaPaymentAccount
- Raw dc+sd-jwt document: https://raw.githubusercontent.com/decentralised-dataexchange/verifiable-data-registry/main/credentialSchemas/claimPathPointer/scaPaymentAccount/2025.7.1/dc+sd-jwt.schema.json
- The metadata file sits next to each schema file, with the suffix
.schema.metadata.json. It carries the title, the credential type, the doctype and the format flags.
Cross-references
igrantio-credential-schema-sca-payment-card- the payment card credential.igrantio-credential-schema-sca-payment-user- the payment user credential.igrantio-api-issuer- the create credential definition and issue credential operations, and the transaction data validation operation.igrantio-api-verifier- the DCQL query that asks a holder for the credential.igrantio-ows-overview- architecture and glossary.