Skip to main content
Version: 11.3.0

Entra Verified ID for HYPR Affirm

When a requester successfully completes a HYPR Affirm verification flow, HYPR can issue a Microsoft Entra Verified ID credential as the outcome. The credential is stored in Microsoft Authenticator. A later Verified Credential step accepts the credential only if its revocation ID matches the requester's login identifier.

This integration requires defining a verifiable credential in Entra ID, then connecting it to HYPR Affirm using the authority ID, credential type and manifest contract ID values obtained from Entra.

Prerequisites

This outcome requires an Entra ID integration enabled in HYPR and an Entra app registration with the correct permissions. See Entra ID Application Setup for HYPR Affirm. Entra must provide a username (UPN) for all target users. The issued credential's given name and family name come from the user's first and last name, or from the username when those are missing. Additional attributes can be required depending on your verification flow configuration.

For where the Verified ID outcome is selected in the verification flow editor, see Configure Verification Steps → Verified Outcome.

First, define the credential to be used, then assign it to the desired application and use the resulting values in HYPR Control Center.

Define the Issuable Verifiable Credential in Entra ID​

  1. As an Entra ID user with administrative rights, search for Verified ID. Click the result of the same name to open the Verified ID Overview.

  2. Click + Create Credential.

    Verified ID Overview page with the Create credential button, basic organization information and existing credentials
  3. The following dialog opens. Choose Custom credential and click Next.

    Create credential page with Custom credential selected under Select a credential type and the Next button
  4. The Create a new credential dialog appears.

    Create a new credential page with Credential name, Display definition and Rules definition fields and the Create button

    Complete the fields as follows:

    • Type Verified Credential Expert into Credential name.

    • Copy the following code into the Display definition, replacing the logo.uri value with a link to your own logo. The logo must be reachable anonymously over the internet for the wallet to render it.

      {
      "locale": "en-US",
      "card": {
      "title": "Verified Credential Expert",
      "issuedBy": "Microsoft",
      "backgroundColor": "#000000",
      "textColor": "#ffffff",
      "logo": {
      "uri": "https://your-org.example.com/your-credential-logo.png",
      "description": "Verified Credential Expert Logo"
      },
      "description": "Use your verified credential to prove to anyone that you know all about verifiable credentials."
      },
      "consent": {
      "title": "Do you want to get your Verified Credential?",
      "instructions": "Sign in with your account to get your card."
      },
      "claims": [
      {
      "claim": "vc.credentialSubject.firstName",
      "label": "First name",
      "type": "String"
      },
      {
      "claim": "vc.credentialSubject.lastName",
      "label": "Last name",
      "type": "String"
      }
      ]
      }
    • Copy the following code into the Rules definition field:

      {
      "attestations": {
      "idTokenHints": [
      {
      "mapping": [
      {
      "outputClaim": "firstName",
      "required": true,
      "inputClaim": "$.given_name",
      "indexed": false
      },
      {
      "outputClaim": "lastName",
      "required": true,
      "inputClaim": "$.family_name",
      "indexed": true
      }
      ],
      "required": false
      }
      ]
      },
      "validityInterval": 2592000,
      "vc": {
      "type": [
      "VerifiedCredentialExpert"
      ]
      }
      }
    • When you are finished, click Create.

  5. A confirmation page displays. Continue to Obtaining Values for HYPR Affirm.

    Verified Credential Expert details page with the credential preview, credential details and Issue a credential under Manage

Obtaining Values for HYPR Affirm​

  1. If you are not already on the Verified ID page, browse to it.

  2. Select Verified Credential Expert (or the name of your credential, if different).

    Verified Credential Expert details page with the credential preview, credential details and Issue a credential under Manage
  3. Click Manage > Issue a credential in the left navigation menu.

    Issue a credential page with the Request body showing the authority, type and manifest values
  4. From the Request body pane, copy the authority, type and manifest values. You need only part of each value, as follows:

    • authority — corresponds to the Authority ID field when configuring the Verified Outcome step
      • Full value: did:web:verifiedid.entra.microsoft.com:aaaaaaaa-1111-2222-3333-aaaaaaaaaaaa:bbbbbbbb-4444-5555-6666-bbbbbbbbbbbb
      • Copy this part: bbbbbbbb-4444-5555-6666-bbbbbbbbbbbb
    • type — corresponds to the Type field when configuring the Verified Outcome step
      • Full value: VerifiedCredentialExpert
      • Copy this part: VerifiedCredentialExpert
    • manifest — corresponds to the Manifest Contract ID field when configuring the Verified Outcome step
      • Full value: https://verifiedid.did.msidentity.com/v1.0/tenants/aaaaaaaa-1111-2222-3333-aaaaaaaaaaaa/verifiableCredentials/contracts/cccccccc-7777-8888-9999-cccccccccccc/manifest
      • Copy this part: cccccccc-7777-8888-9999-cccccccccccc
See also

For configuring identity verification (IdV) flows, see Creating and Managing Verification Flows.

Assign Entra ID Application Permissions​

For step-by-step instructions on registering an Entra app and configuring the required Verifiable Credentials permissions, see Entra ID Application Setup for HYPR Affirm: Entra Verified ID.