Skip to main content

Check a credential’s status

You can check whether a credential is valid or revoked by using the Status List Service. The Status List Service supports and publicly hosts 2 different list formats:

A status list is a signed JSON web token (JWT). You can verify the JWT’s signature by accessing the Status List Service’s JSON web key set (JWKS) hosted at:

  • https://crs.account.gov.uk/.well-known/jwks.json (production)
  • https://crs.integration.account.gov.uk/.well-known/jwks.json(integration)

The Status List Service stores each credential status at a specific index in a status list. A status is represented by 2 bits. A status index may contain one of the following bit combinations:

Bit combination Validity Explanation
00 VALID Represents a valid credential.
01 INVALID Represents a credential that has been permanently revoked by the Status List Service.

Decode the credential

To check the status of a credential, you can query the Status List Service by sending a GET request to the relevant status list. You will need to decode the credential to find the:

  • status uri that identifies the specific status list you need to query
  • credential’s universally unique identifier (UUID) to locate the right status index

Send your request to the status list endpoint

To check a credential’s status, send a GET request to the status list endpoint you identified when you decoded the credential. You must include the decoded credential UUID in your request.

Query a bitstring status list

Bitstring status lists have URI paths that begin with /b/. These status lists follow the more complex implementation of the W3C Bitstring Status List specification.

This is an example of a GET request to /b/{statusListIdentifier}:

GET /b/A671FED3E9AD HTTP/1.1
Host: crs.account.gov.uk

You’ll receive the credential’s status information as a JWT with a header and a payload.

The JWT response header will contain the following:

{
  "alg": "ES256",
  "kid": "12",
  "typ": "vc+jwt"
}
Parameter Description
alg alg stands for ‘algorithm’. This value will be returned as ES256. This is the algorithm used to encode the JWT.
kid kid stands for ‘key ID’. This key ID represents a key in the Status List Service’s JWKS which can be used to verify the JSON web signature (JWS).
typ typ stands for ‘type’. This is the type of the status list. It is vc+jwt for Bitstring status lists.

The JWT response payload for a bitstring status list will contain the following:

{
  "@context": [
    "https://www.w3.org/ns/credentials/v2",
    "https://www.w3.org/ns/credentials/examples/v2"
  ],
  "id": "https://crs.account.gov.uk/b/A671FED3E9AD",
  "type": [
    "VerifiableCredential",
    "BitstringStatusListCredential"
  ],
  "issuer": "https://crs.account.gov.uk/",
  "validFrom": "2025-10-01T14:00:00Z",
  "validUntil": "2025-10-08T14:00:00Z",
  "credentialSubject": {
    "id": "https://crs.account.gov.uk/b/A671FED3E9AD#list",
    "type": "BitstringStatusList",
    "statusSize": 2,
    "statusPurpose": "message",
    "statusMessage": [
      {
        "status": "0x0",
        "message": "VALID"
      },
      {
        "status": "0x1",
        "message": "INVALID"
      }
    ],
    "encodedList": "uH4sIAAAAAAAAA3MUBABJTAvCAgAAAA",
    "ttl": "3600"
  }
}
Parameter Description
id A unique URL that represents this status list.
type The type of credential.
issuer The URL of this status list credential’s issuer.
validFrom The earliest point in time at which the status list is valid.
validUntil The latest point in time at which the status list is valid.
credentialSubject The status list subject about which the claims below are made.
credentialSubject.id A unique URI that represents this status list.
credentialSubject.type The type of credential. This will be BitstringStatusList.
credentialSubject.statusSize The size of the status list in bits.
credentialSubject.statusPurpose The purpose of the status list, as described in statusMessage.
credentialSubject.statusMessages This is an array of objects, which each contain a status and a message.
credentialSubject.statusMessages.status This represents the status value in the status list. It is a hexadecimal string, and will be "0x0" or "1x1".
credentialSubject.statusMessages.message The status message representing the status value. This will be "VALID" or "INVALID".
credentialSubject.encodedList This is a multibase-encoded base64url (with no padding) representation of the GZIP-compressed bitstring values for the associated range of verifiable credential status values.

Query a token status list

Token status lists have URI paths that begin with /t/. These status lists follow the IETF Token Status List specification.

This is an example of a GET request to /t/{statusListIdentifier}:

GET /t/A671FED3E9AD HTTP/1.1
Host: crs.account.gov.uk

You’ll receive the credential’s status information as a JWT response with a header and a payload.

The JWT response header will contain the following:

{
  "alg": "ES256",
  "kid": "12",
  "typ": "statuslist+jwt"
}
Parameter Description
alg alg stands for ‘algorithm’. This value will be returned as ES256. This is the algorithm used to encode the JWT.
kid kid stands for ‘key ID’. This key ID represents a key in the Status List Service’s JWKS which can be used to verify the JSON web signature (JWS).
typ typ stands for ‘type’. This is the type of the status list. This will be statuslist+jwt for a Token status list.

The JWT response payload for a token status list will contain the following:

{
  "exp": 2291720170,
  "iat": 1686920170,
  "iss": "https://crs.account.gov.uk",
  "status_list": {
    "bits": 2,
    "lst": "eNpzdAEAAMgAhg"
  },
  "sub": "https://crs.account.gov.uk/b/A671FED3E9AD",
  "ttl": 43200
}
Parameter Description
exp exp stands for ‘expiry’. This is the expiry of the subject credential, expressed in epoch seconds.
iat iat stands for ‘issued at’. This is the UNIX timestamp the subject credential was originally issued at, in epoch seconds.
iss iss stands for ‘issuer’. This is the URL of the credential issuer service operated by the organisation sharing the credential.
status_list.bits The number of bits that represent a status.
status_list.lst lst stands for ‘list’. This is an encoded version of this status list.
sub sub stands for ‘subject’. This is the URI of the status list that was in the original HTTP request.
ttl ttl stands for ‘time-to-live’. This is the lifetime of the cached version of this status list. Status lists are updated at regular and set intervals.

Test querying a credential’s status

You can also use the mock Status List Service to test querying a credential’s status in the GOV.UK Wallet Sandbox.

Verify a status list’s JSON Web Key Set (JWKS)

The JWKS endpoint exposes the Status List Service’s public cryptographic keys in JSON Web Key Set (JWKS) format. You can use a public key to verify the signature of a status list. This verification lets you make sure the Status List Service published this status list and it has not been tampered with.

Endpoint location

The JWKS is publicly accessible at the standardised location /.well-known/jwks.json on the Status List Service domain.

Response format

The endpoint must return a 200 OK HTTP status code and a valid JSON response that follows the JWKS specification defined in RFC 7517. Each key within the JWKS is represented as a JSON Web Key (JWK) object. The JWKS usually contains only one key, but it can contain two keys during a key rotation overlap period.

The JWK for an elliptic curve public key based on the P-256 curve must include the following parameters:

Parameter Definition
kty The family of cryptographic algorithms used with the key. This must be EC.
kid A unique identifier for a specific key within the set. This value will be referenced in the status list JWT header to show which key must be used for verification. This parameter is important for associating the correct public key with the status list being verified.
crv The cryptographic curve used with the key. This must be P-256.
x The “x” coordinate for the elliptic curve point.
y The “y” coordinate for the elliptic curve point.
alg The cryptographic algorithm used with the key. This must be ES256.
use The intended use of the key. This must be sig to indicate the key can be used to verify the signature.

JWKS example

Below is an example of a JWKS containing one elliptic curve public key based on the P-256 curve:

{
  "keys": [
    {
      "kty": "EC",
      "use": "sig",
      "crv": "P-256",
      "kid": "5dcbee863b5d7cc30c9ba1f7393dacc6c16610782e4b6a191f94a7e8b1e1510f",
      "x": "6jCKX_QRrmTeEJi-uiwcYqu8BgMgl70g2pdAst24MPE",
      "y": "icPzjbSk6apD_SNvQt8NWOPlPeGG4KYU55GfnARryoY",
      "alg": "ES256"
    }
  ]
}
This page was last reviewed on 16 September 2026. It needs to be reviewed again on 16 March 2027 by the page owner #di-mobile-wallet-tech-docs .