Check a credential’s status
You can check whether a credential is valid or revoked by using the Status List Service. The Status List Service supports and publicly hosts 2 different list formats:
A status list is a signed JSON web token (JWT). You can verify the JWT’s signature by accessing the Status List Service’s JSON web key set (JWKS) hosted at:
https://crs.account.gov.uk/.well-known/jwks.json(production)https://crs.integration.account.gov.uk/.well-known/jwks.json(integration)
The Status List Service stores each credential status at a specific index in a status list. A status is represented by 2 bits. A status index may contain one of the following bit combinations:
| Bit combination | Validity | Explanation |
|---|---|---|
| 00 | VALID | Represents a valid credential. |
| 01 | INVALID | Represents a credential that has been permanently revoked by the Status List Service. |
Decode the credential
To check the status of a credential, you can query the Status List Service by sending a GET request to the relevant status list. You will need to decode the credential to find the:
- status
urithat identifies the specific status list you need to query - credential’s universally unique identifier (UUID) to locate the right status index
Send your request to the status list endpoint
To check a credential’s status, send a GET request to the status list endpoint you identified when you decoded the credential. You must include the decoded credential UUID in your request.
Query a bitstring status list
Bitstring status lists have URI paths that begin with /b/. These status lists follow the more complex implementation of the W3C Bitstring Status List specification.
This is an example of a GET request to /b/{statusListIdentifier}:
GET /b/A671FED3E9AD HTTP/1.1
Host: crs.account.gov.uk
You’ll receive the credential’s status information as a JWT with a header and a payload.
The JWT response header will contain the following:
{
"alg": "ES256",
"kid": "12",
"typ": "vc+jwt"
}
| Parameter | Description |
|---|---|
alg |
alg stands for ‘algorithm’. This value will be returned as ES256. This is the algorithm used to encode the JWT. |
kid |
kid stands for ‘key ID’. This key ID represents a key in the Status List Service’s JWKS which can be used to verify the JSON web signature (JWS). |
typ |
typ stands for ‘type’. This is the type of the status list. It is vc+jwt for Bitstring status lists. |
The JWT response payload for a bitstring status list will contain the following:
{
"@context": [
"https://www.w3.org/ns/credentials/v2",
"https://www.w3.org/ns/credentials/examples/v2"
],
"id": "https://crs.account.gov.uk/b/A671FED3E9AD",
"type": [
"VerifiableCredential",
"BitstringStatusListCredential"
],
"issuer": "https://crs.account.gov.uk/",
"validFrom": "2025-10-01T14:00:00Z",
"validUntil": "2025-10-08T14:00:00Z",
"credentialSubject": {
"id": "https://crs.account.gov.uk/b/A671FED3E9AD#list",
"type": "BitstringStatusList",
"statusSize": 2,
"statusPurpose": "message",
"statusMessage": [
{
"status": "0x0",
"message": "VALID"
},
{
"status": "0x1",
"message": "INVALID"
}
],
"encodedList": "uH4sIAAAAAAAAA3MUBABJTAvCAgAAAA",
"ttl": "3600"
}
}
| Parameter | Description |
|---|---|
id |
A unique URL that represents this status list. |
type |
The type of credential. |
issuer |
The URL of this status list credential’s issuer. |
validFrom |
The earliest point in time at which the status list is valid. |
validUntil |
The latest point in time at which the status list is valid. |
credentialSubject |
The status list subject about which the claims below are made. |
credentialSubject.id |
A unique URI that represents this status list. |
credentialSubject.type |
The type of credential. This will be BitstringStatusList. |
credentialSubject.statusSize |
The size of the status list in bits. |
credentialSubject.statusPurpose |
The purpose of the status list, as described in statusMessage. |
credentialSubject.statusMessages |
This is an array of objects, which each contain a status and a message. |
credentialSubject.statusMessages.status |
This represents the status value in the status list. It is a hexadecimal string, and will be "0x0" or "1x1". |
credentialSubject.statusMessages.message |
The status message representing the status value. This will be "VALID" or "INVALID". |
credentialSubject.encodedList |
This is a multibase-encoded base64url (with no padding) representation of the GZIP-compressed bitstring values for the associated range of verifiable credential status values. |
Query a token status list
Token status lists have URI paths that begin with /t/. These status lists follow the IETF Token Status List specification.
This is an example of a GET request to /t/{statusListIdentifier}:
GET /t/A671FED3E9AD HTTP/1.1
Host: crs.account.gov.uk
You’ll receive the credential’s status information as a JWT response with a header and a payload.
The JWT response header will contain the following:
{
"alg": "ES256",
"kid": "12",
"typ": "statuslist+jwt"
}
| Parameter | Description |
|---|---|
alg |
alg stands for ‘algorithm’. This value will be returned as ES256. This is the algorithm used to encode the JWT. |
kid |
kid stands for ‘key ID’. This key ID represents a key in the Status List Service’s JWKS which can be used to verify the JSON web signature (JWS). |
typ |
typ stands for ‘type’. This is the type of the status list. This will be statuslist+jwt for a Token status list. |
The JWT response payload for a token status list will contain the following:
{
"exp": 2291720170,
"iat": 1686920170,
"iss": "https://crs.account.gov.uk",
"status_list": {
"bits": 2,
"lst": "eNpzdAEAAMgAhg"
},
"sub": "https://crs.account.gov.uk/b/A671FED3E9AD",
"ttl": 43200
}
| Parameter | Description |
|---|---|
exp |
exp stands for ‘expiry’. This is the expiry of the subject credential, expressed in epoch seconds. |
iat |
iat stands for ‘issued at’. This is the UNIX timestamp the subject credential was originally issued at, in epoch seconds. |
iss |
iss stands for ‘issuer’. This is the URL of the credential issuer service operated by the organisation sharing the credential. |
status_list.bits |
The number of bits that represent a status. |
status_list.lst |
lst stands for ‘list’. This is an encoded version of this status list. |
sub |
sub stands for ‘subject’. This is the URI of the status list that was in the original HTTP request. |
ttl |
ttl stands for ‘time-to-live’. This is the lifetime of the cached version of this status list. Status lists are updated at regular and set intervals. |
Test querying a credential’s status
You can also use the mock Status List Service to test querying a credential’s status in the GOV.UK Wallet Sandbox.
Verify a status list’s JSON Web Key Set (JWKS)
The JWKS endpoint exposes the Status List Service’s public cryptographic keys in JSON Web Key Set (JWKS) format. You can use a public key to verify the signature of a status list. This verification lets you make sure the Status List Service published this status list and it has not been tampered with.
Endpoint location
The JWKS is publicly accessible at the standardised location /.well-known/jwks.json on the Status List Service domain.
Response format
The endpoint must return a 200 OK HTTP status code and a valid JSON response that follows the JWKS specification defined in RFC 7517. Each key within the JWKS is represented as a JSON Web Key (JWK) object. The JWKS usually contains only one key, but it can contain two keys during a key rotation overlap period.
The JWK for an elliptic curve public key based on the P-256 curve must include the following parameters:
| Parameter | Definition |
|---|---|
kty |
The family of cryptographic algorithms used with the key. This must be EC. |
kid |
A unique identifier for a specific key within the set. This value will be referenced in the status list JWT header to show which key must be used for verification. This parameter is important for associating the correct public key with the status list being verified. |
crv |
The cryptographic curve used with the key. This must be P-256. |
x |
The “x” coordinate for the elliptic curve point. |
y |
The “y” coordinate for the elliptic curve point. |
alg |
The cryptographic algorithm used with the key. This must be ES256. |
use |
The intended use of the key. This must be sig to indicate the key can be used to verify the signature. |
JWKS example
Below is an example of a JWKS containing one elliptic curve public key based on the P-256 curve:
{
"keys": [
{
"kty": "EC",
"use": "sig",
"crv": "P-256",
"kid": "5dcbee863b5d7cc30c9ba1f7393dacc6c16610782e4b6a191f94a7e8b1e1510f",
"x": "6jCKX_QRrmTeEJi-uiwcYqu8BgMgl70g2pdAst24MPE",
"y": "icPzjbSk6apD_SNvQt8NWOPlPeGG4KYU55GfnARryoY",
"alg": "ES256"
}
]
}