OUTCOME · Discover
What changes
Read-only projection; it grants no mutation, settlement, traffic, or authority change.
v2Trust & identity
/api/v2/trust/credentialsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Discover the subject's credential portfolio and reconcile lifecycle, issuer proof posture, and commitments before selecting one for a relying workflow.
OUTCOME · Discover
Read-only projection; it grants no mutation, settlement, traffic, or authority change.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the trust:read scope.EXAMPLEBearer hc_live_…
cursorqueryOptionalopaque stringnext_cursor from the preceding page; valid only for the same subject and filter set.EXAMPLEpage-two
limitqueryOptionalinteger · 1–200 · default 50Maximum credentials to return.EXAMPLE50
statusqueryOptionaluppercase lifecycle state · 2–32Exact canonical credential lifecycle filter.EXAMPLEVALID
qqueryOptionalstring · max 200, no control charactersCase-insensitive search term.EXAMPLEage
RESPONSES
{
"items": [
{
"credential_id": "ffffffffffffffffffffffffffffffff",
"credential_type": "IDENTITY_ATTESTATION",
"issuer": "did:web:id.hybrid-chain.com",
"status": "VALID",
"valid_from": "2026-09-01T00:00:00Z",
"valid_until": "2027-09-01T00:00:00Z",
"updated_at": "2026-09-01T00:00:00Z",
"proof_type": "HybridZkKnownDataProof2026",
"issuer_signature_valid": true,
"commitments": [
{
"key": "age_over_18",
"commitment": "dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd",
"encoding": "Hybrid-Chain-ZK-v1/NFC/TRIM/SHA-256",
"proof_type": "HybridZkKnownDataProof2026",
"value_type": "BOOLEAN",
"assurance_level": "HC-IAL2",
"verification_status": "VERIFIED"
}
]
}
],
"next_cursor": null
}{
"code": "invalid_credential_query",
"message": "limit, status, q, or cursor is outside the published contract."
}invalid_credential_query{
"code": "invalid_credentials",
"message": "The bearer credential is missing or invalid."
}invalid_credentials{
"code": "insufficient_scope",
"message": "The credential lacks exact trust:read authority."
}insufficient_scope{
"code": "identity_unavailable",
"message": "The authoritative Identity trust service is unavailable."
}identity_unavailableOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗