Convenience library based on okhttp and gson to interact with aries cloud agent python (aca-py) instances.
<dependency>
<groupId>network.idu.acapy</groupId>
<artifactId>aries-client-python</artifactId>
<version>0.10.0</version>
</dependency>
-
Why don't you use swagger codegen?
For a long time aca-py's swagger.json was not really in sync with the code base. This has been hugely improved lately, so I started to generate model classes based on the stable releases found on dockerhub. There are still issues with complex structures, so one can not simply use the models 1:1, instead each one has to be checked manually before using it. This is tedious work and might take a while to complete. Also, the api is complex so that I found it useful to introduce helper methods directly in the model classes to make them more accessible.
-
Why is endpoint X, or field Y missing?
aca-py's api is changing rapidly with each release, and until most of the classes are using the generated models this can happen. So, if you are missing something create a PR with a fix or open an issue.
Client Version | ACA-PY Version |
---|---|
0.10.0 | 0.10.x |
0.8.0 | 0.8.0 |
0.7.0 | 0.7.0 |
0.7.6 | 0.7.1, 0.7.2 |
>= 0.7.18 | 0.7.3 |
>= 0.7.25 | 0.7.4 |
>= 0.7.32 | 0.7.5 |
Method | Endpoint | Implemented |
---|---|---|
action-menu | ||
POST | /action-menu/{conn_id}/close | β |
POST | /action-menu/{conn_id}/fetch | β |
POST | /action-menu/{conn_id}/perform | β |
POST | /action-menu/{conn_id}/request | β |
POST | /action-menu/{conn_id}/send-menu | β |
basicmessage | ||
POST | /connections/{conn_id}/send-message | β |
connection | ||
GET | /connections | β |
POST | /connections/create-invitation | β |
POST | /connections/create-static | β |
POST | /connections/receive-invitation | β |
GET | /connections/{conn_id}} | β |
DELETE | /connections/{conn_id} | β |
POST | /connections/{conn_id}/accept-invitation | β |
POST | /connections/{conn_id}/accept-request | β |
GET | /connections/{conn_id}/endpoints | β |
POST | /connections/{conn_id}/establish-inbound/{ref_id} | β |
GET | /connections/{conn_id}/metadata | β |
POST | /connections/{conn_id}/metadata | β |
credential-definition | ||
POST | /credential-definitions | β |
GET | /credential-definitions/created | β |
GET | /credential-definitions/{cred_def_id} | β |
POST | /credential-definitions/{cred_def_id}/write_record | β |
credentials | ||
GET | /credentials/mime-types/{credential_id} | β |
GET | /credentials/revoked/{credential_id} | β |
GET | /credential/w3c/{credential_id} | β |
DELETE | /credential/w3c/{credential_id} | β |
GET | /credential/{credential_id} | β |
DELETE | /credential/{credential_id} | β |
GET | /credentials | β |
POST | /credentials/w3c | β |
did-exchange | ||
POST | /didexchange/create-request | β |
POST | /didexchange/receive-request | β |
POST | /didexchange/{conn_id}/accept-invitation | β |
POST | /didexchange/{conn_id}/accept-request | β |
POST | /didexchange/{conn_id}/reject | β |
discover-features | ||
GET | /discover-features/query | β |
GET | /discover-features/records | β |
discover-features v2.0 | ||
GET | /discover-features-2.0/queries | β |
GET | /discover-features-2.0/records | β |
endorse-transaction | ||
POST | /transaction/{tran_id}/resend | β |
POST | /transactions | β |
POST | /transactions/create-request | β |
POST | /transactions/{conn_id}/set-endorser-info | β |
POST | /transactions/{conn_id}/set-endorser-role | β |
POST | /transactions/{tran_id} | β |
POST | /transactions/{tran_id}/cancel | β |
POST | /transactions/{tran_id}/endorse | β |
POST | /transactions/{tran_id}/refuse | β |
POST | /transactions/{tran_id}/write | β |
introduction | ||
POST | /connections/{conn_id}/start-introduction | β |
issue-credential v1.0 | ||
POST | /issue-credential/create | β |
POST | /issue-credential/create-offer | β |
GET | /issue-credential/records | β |
GET | /issue-credential/records/{cred_ex_id} | β |
DELETE | /issue-credential/records/{cred_ex_id} | β |
POST | /issue-credential/records/{cred_ex_id}/issue | β |
POST | /issue-credential/records/{cred_ex_id}/problem-report | β |
POST | /issue-credential/records/{cred_ex_id}/send-offer | β |
POST | /issue-credential/records/{cred_ex_id}/send-request | β |
POST | /issue-credential/records/{cred_ex_id}/store | β |
POST | /issue-credential/send | β |
POST | /issue-credential/send-offer | β |
POST | /issue-credential/send-proposal | β |
issue-credential v2.0 | ||
POST | /issue-credential-2.0/create | β |
POST | /issue-credential-2.0/create-offer | β |
GET | /issue-credential-2.0/records | β |
GET | /issue-credential-2.0/records/{cred_ex_id} | β |
DELETE | /issue-credential-2.0/records/{cred_ex_id} | β |
POST | /issue-credential-2.0/records/{cred_ex_id}/issue | β |
POST | /issue-credential-2.0/records/{cred_ex_id}/problem-report | β |
POST | /issue-credential-2.0/records/{cred_ex_id}/send-offer | β |
POST | /issue-credential-2.0/records/{cred_ex_id}/send-request | β |
POST | /issue-credential-2.0/records/{cred_ex_id}/store | β |
POST | /issue-credential-2.0/send | β |
POST | /issue-credential-2.0/send-offer | β |
POST | /issue-credential-2.0/send-proposal | β |
POST | /issue-credential-2.0/send-request | β |
jsonld | ||
POST | /jsonld/sign | β |
POST | /jsonld/verify | β |
ledger | ||
GET | /ledger/config | β |
GET | /ledger/did-endpoint | β |
GET | /ledger/did-verkey | β |
GET | /ledger/get-nym-role | β |
GET | /ledger/get-write-ledger | β |
GET | /ledger/get-write-ledgers | β |
POST | /ledger/register-nym | β |
PATCH | /ledger/rotate-public-did-keypair | β |
GET | /ledger/taa | β |
POST | /ledger/taa/accept | β |
POST | /ledger/{ledger_id}/set-write-ledger | β |
mediation | ||
GET | /mediation/default-mediator | β |
DELETE | /mediation/default-mediator | β |
GET | /mediation/keylists | β |
POST | /mediation/keylists/{mediation_id}/send-keylist-query | β |
POST | /mediation/keylists/{mediation_id}/send-keylist-update | β |
POST | /mediation/request/{conn_id} | β |
GET | /mediation/requests | β |
GET | /mediation/requests/{mediation_id} | β |
DELETE | /mediation/requests/{mediation_id} | β |
POST | /mediation/requests/{mediation_id}/deny | β |
POST | /mediation/requests/{mediation_id}/grant | β |
POST | /mediation/update-keylist/{conn_id} | β |
PUT | /mediation/{mediation_id}/default-mediator | β |
multitenancy | ||
POST | /multitenancy/wallet | β |
GET | /multitenancy/wallet/{wallet_id} | β |
PUT | /multitenancy/wallet/{wallet_id} | β |
POST | /multitenancy/wallet/{wallet_id}/remove | β |
POST | /multitenancy/wallet/{wallet_id}/token | β |
GET | /multitenancy/wallets | β |
out-of-band | ||
POST | /out-of-band/create-invitation | β |
POST | /out-of-band/receive-invitation | β |
present-proof v1.0 | ||
POST | /present-proof/create-request | β |
GET | /present-proof/records | β |
GET | /present-proof/records/{pres_ex_id} | β |
DELETE | /present-proof/records/{pres_ex_id} | β |
GET | /present-proof/records/{pres_ex_id}/credentials | β |
POST | /present-proof/records/{pres_ex_id}/problem-report | β |
POST | /present-proof/records/{pres_ex_id}/send-presentation | β |
POST | /present-proof/records/{pres_ex_id}/send-request | β |
POST | /present-proof/records/{pres_ex_id}/verify-presentation | β |
POST | /present-proof/send-proposal | β |
POST | /present-proof/send-request | β |
present-proof v2.0 | ||
POST | /present-proof-2.0/create-request | β |
GET | /present-proof-2.0/records | β |
GET | /present-proof-2.0/records/{pres_ex_id} | β |
DELETE | /present-proof-2.0/records/{pres_ex_id} | β |
GET | /present-proof-2.0/records/{pres_ex_id}/credentials | β |
POST | /present-proof-2.0/records/{pres_ex_id}/problem-report | β |
POST | /present-proof-2.0/records/{pres_ex_id}/send-presentation | β |
POST | /present-proof-2.0/records/{pres_ex_id}/send-request | β |
POST | /present-proof-2.0/records/{pres_ex_id}/verify-presentation | β |
POST | /present-proof-2.0/send-proposal | β |
POST | /present-proof-2.0/send-request | β |
resolver | ||
GET | /resolver/resolve/{did} | β |
revocation | ||
GET | /revocation/active-registry/{cred_def_id} | β |
POST | /revocation/active-registry/{cred_def_id}/rotate | β |
POST | /revocation/clear-pending-revocations | β |
POST | /revocation/create-registry | β |
GET | /revocation/credential-record | β |
POST | /revocation/publish-revocations | β |
GET | /revocation/registries/created | β |
DELETE | /revocation/registry/delete-tails-file | β |
GET | /revocation/registry/{rev_reg_id} | β |
PATCH | /revocation/registry/{rev_reg_id} | β |
POST | /revocation/registry/{rev_reg_id}/definition | β |
POST | /revocation/registry/{rev_reg_id}/entry | β |
PUT | /revocation/registry/{rev_reg_id}/fix-revocation-entry-state | β |
GET | /revocation/registry/{rev_reg_id}/issued | β |
GET | /revocation/registry/{rev_reg_id}/issued/details | β |
GET | /revocation/registry/{rev_reg_id}/issued/indy_recs | β |
PATCH | /revocation/registry/{rev_reg_id}/set-state | β |
PUT | /revocation/registry/{rev_reg_id}/tails-file | β |
GET | /revocation/registry/{rev_reg_id}/tails-file | β |
POST | /revocation/revoke | β |
schema | ||
POST | /schemas | β |
GET | /schemas/created | β |
GET | /schemas/{schema_id} | β |
POST | /schemas/{schema_id}/write_record | β |
settings | ||
PUT | /settings | β |
GET | /settings | β |
trustping | ||
POST | /connections/{conn_id}/send-ping | β |
wallet | ||
GET | /wallet/did | β |
POST | /wallet/did/create | β |
PATCH | /wallet/did/local/rotate-keypair | β |
GET | /wallet/did/public | β |
POST | /wallet/did/public | β |
GET | /wallet/get-did-endpoint | β |
POST | /wallet/jwt/sign | β |
POST | /wallet/jwt/verify | β |
POST | /wallet/set-did-endpoint | β |
server | ||
GET | /plugins | β |
GET | /shutdown | β |
GET | /status | β |
GET | /status/config | β |
GET | /status/live | β |
GET | /status/ready | β |
POST | /status/reset | β |
The rest client is used to send requests against aca-py's admin rest endpoint.
Related aca-py config flags are: --admin <host> <port>
, --admin-api-key <api-key>
The default assumes you are running against a single wallet. In case of multi tenancy with base and sub wallets the bearerToken needs to be set as well.
Example aca-py config flags:
--admin 0.0.0.0 8031
--admin-api-key secret
Example client builder:
AriesClient ac = AriesClient
.builder()
.url("http://localhost:8031") // optional - defaults to localhost:8031
.apiKey("secret") // optional - admin api key if set
.bearerToken("123.456.789") // optional - jwt token - only when running in multi tenant mode
.build();
With aca-py you have three options on how to receive status changes:
- Poll the rest API - this is not recommended
- Register a webhook URL
- Connect to aca-py's websocket
Related aca-py config flag: --webhook-url <url#api_key>
If running a single wallet and not in multi tenant mode.
Example aca-py config flag: --webhook-url http://localhost:8080/webhook
@Controller
public class WebhookController {
private EventHandler handler = new EventHandler.DefaultEventHandler();
@Post("/webhook/topic/{topic}")
public void handleWebhookEvent(
@PathVariable String topic,
@Body String payload) {
handler.handleEvent(topic, payload);
}
}
If running in multi tenant mode.
Example aca-py config flags:
--webhook-url http://localhost:8080/webhook
--multitenant
--jwt-secret 1234
--multitenant-admin
Example multi tenant webhook controller
@Controller
public class WebhookController {
private EventHandler handler = new TenantAwareEventHandler.DefaultTenantAwareEventHandler();
@Post("/webhook/topic/{topic}")
public void handleWebhookEvent(
@PathVariable String topic,
@Body String payload,
HttpRequest request) {
String walletId = request.getHeaders().get("x-wallet-id");
handler.handleEvent(walletId, topic, payload);
}
}
If the admin api is enabled aca-py also supports a websocket endpoint under ws(s)://<host>:<admin-port>/ws
Example aca-py config flag: --admin 0.0.0.0 8031
To connect with the websocket you can use the AriesWebSocketClient
like:
@Factory
public class AriesSocketFactory {
@Value("${acapy.ws.url}")
private String url;
@Value("${acapy.admin.apiKey}")
private String apiKey;
@Singleton
@Bean(preDestroy = "closeWebsocket")
public AriesWebSocketClient ariesWebSocketClient() {
return AriesWebSocketClient
.builder()
.url(url) // optional - defaults to ws://localhost:8031/ws
.apiKey(apiKey) // optional - admin api key if set
.handler(new EventHandler.DefaultEventHandler()) // optional - your handler implementation
// .bearerToken(bearer) // optional - jwt token - only when running in multi tenant mode
.build();
}
}
To add your own event handler implementation to use in webhooks or in the websocket client, you can either extend or instantiate one of the following classes:
EventHandler
TenantAwareEventHandler
ReactiveEventHandler
All classes take care of type conversion so that you can immediately start implementing your business logic.
@Singleton
public class MyHandler extends EventHandler {
@Override
public void handleProof(PresentationExchangeRecord proof) {
if (proof.roleIsVerifierAndVerified()) { // received a validated proof
MyCredential myCredential = proof.from(MyCredential.class);
// If the presentation is based on multiple credentials this can be done multiple times
// given that the POJO is annotated with @AttributeGroup e.g.
MyOtherCredential otherCredential = proof.from(MyOtherCredential.class);
}
}
}
As the websocket client already implements the EventHandler interface you can directly use it like:
AriesWebSocketClient ws = AriesWebSocketClient.builder().build();
// do some stuff, create a connection, or receive invitation
// blocking wait
ConnectionRecord active = ws.connection()
.filter(ConnectionRecord::stateIsActive)
.blockFirst(Duration.ofSeconds(5));
// none blocking
ws.connection()
.filter(ConnectionRecord::stateIsActive)
.subscribe(System.out::println);
The library assumes credentials are flat Pojo's like:
@Data @NoArgsConstructor @Builder
@AttributeGroupName("referent") // the referent that should be matched in the proof request
public final class MyCredential {
private String street;
@AttributeName("e-mail")
private String email; // schema attribute name is e-mail
@AttributeName(excluded = true)
private String comment; // internal field
}
How fields are serialised/deserialized can be changed by using the @AttributeName
or @AttributeGroupName
annotations.
ac.connectionsReceiveInvitation(
ReceiveInvitationRequest.builder()
.did(did)
.label(label)
.build(),
ConnectionReceiveInvitationFilter
.builder()
.alias("alias")
.build())
.ifPresent(connection -> {
log.debug("{}", connection.getConnectionId());
});
MyCredential myCredential = MyCredential
.builder()
.email("test@myexample.com")
.build();
ac.issueCredentialSend(
new V1CredentialProposalRequest(connectionId, credentialdefinitionId, myCredential));
PresentProofRequest proofRequest = PresentProofRequestHelper.buildForEachAttribute(
connectionId,
MyCredential.class,
ProofRestrictions.builder()
.credentialDefinitionId(credentialDefinitionId)
.build());
ac.presentProofSendRequest(proofRequest);
Connectionless proofs are more a thing of mobile wallets, because mostly they involve something that is presented to a human like a barcode, but the java client supports this by providing models and builders.
A flow has the usually following steps:
- The user is presented with a QRCode that contains an invitation URL like: https://myhost.com/url/1234
- The server side HTTP handler of this URL responds with an HTTP.FOUND response that has the proof request encoded in the m parameter
- The mobile wallet tries to match a stored credential, and then responds with a proof presentation if possible
- The server side WebhookHandler waits for the proof and then triggers further actions
@Get("/url/{requestId}")
public HttpResponse<Object> connectionLessProof(@QueryValue String requestId) {
boolean matchingRequest = false; // TODO manage request states
String proofRequestBase64 = ""; // TODO on how to build this see the example below
if (matchingRequest) {
return HttpResponse
.status(HttpStatus.FOUND)
.header("location", deploymentUri + "?m=" + proofRequestBase64;
}
return HttpResponse.notFound();
}
Proof Request Builder Example
ProofRequestPresentationBuilder builder = new ProofRequestPresentationBuilder(ariesClient);
PresentProofRequest presentProofRequest = PresentProofRequestHelper.buildForEachAttribute(
connectionId,
List.of("name", "email"),
ProofRestrictions
.builder()
.schemaId("WgWxqztrNooG92RXvxSTWv:2:schema_name:1.0")
.build());
Optional<String> base64 = builder.buildRequest(presentProofRequest);