France Identité HAIP flow — x509_san_dns:eudi.pcheese.net. The verifier publishes a signed OID4VP request object at request_uri; the wallet fetches it via request_uri_method=post and POSTs the encrypted direct_post.jwt response to response_uri. See France Identité playground — invocation example.
On the phone that has France Identité, tap to open the wallet directly via the openid4vp:// deep link (app-switch), instead of scanning a QR from another device. The wallet POSTs to the same response_uri and this page polls for it.
request_uri.request_uri (request.php?request=<id>). Normally you never copy it — the wallet fetches it automatically after opening the openid4vp:// link. Use this for debugging: paste into jwt.io or curl the request_uri to inspect header/payload, aud, nonce, dcql_query.
openid4vp:// invocation.Scan this QR with France Identité on your phone. The wallet POSTs its vp_token (response_mode=direct_post.jwt) to the public response_uri; this page polls for it and decodes it below on arrival.
This view polls status.php?request=<id> every 2s. After the wallet POSTs, the server logs, attempts JWE decryption using the private/symmetric key matching the selected alg/enc advertised in client_metadata.jwks, validates state/nonce, and stores the result for this transaction. Check logs/<request_id>.log on the server for full headers and raw body.
| Request ID | |
| Request URI | |
| request_uri_method | |
| Response URI | |
| Redirect URI | |
| alg / enc | |
| Status API | |
| Debug page |
certs/ (filesystem, not served). Per the selected alg, the verifier advertises the matching public JWK in client_metadata.jwks (EC P-256 for ECDH-ES*, RSA-2048 for RSA*, OCT for A*KW/dir/PBES2). The matching private key (or symmetric oct / PBES2 password) decrypts the wallet’s direct_post.jwt. Signing key at certs/signing_private.pem signs the request JWT (ES256). Override lib/config.php → BASE_URL must be an https:// origin reachable by the wallet. All alg/enc values come from the IANA JOSE registry (RFC 7518 §4.1). www/qrcode.js (Kazuhiko Arase, MIT) renders invocation_url to <canvas> client-side — no backend change.