Use @authbound/server from a Next.js App Router server route or server action to create credential definitions and OpenID4VCI wallet offers. The SDK speaks to the public API at https://api.authbound.io using your secret key.
Issuance always runs on the server. Never create offers or definitions from a client component, route handler that runs on the edge with browser env vars, or any code that ships your secret key to the browser.

Install

Environment

.env.local

Initialize once

Create a small server-only module so the client is reused across requests.
lib/authbound.ts

Ensure a credential definition exists

Definitions are project-scoped templates. Create them once at boot or lazily when an offer is requested. The pattern below tries to load the definition first and creates it only when missing.
lib/credential-definitions.ts
If two processes run this helper at the same time, the slower create fails with HTTP 409 and code credential_definition_conflict. Catch that and call get again.

Create an offer with a Server Action

The simplest way to hand a wallet offer to the user from an App Router page is a server action that returns the public fields the browser needs.
app/issue/pension/actions.ts

Render the wallet handoff

app/issue/pension/page.tsx
For desktop, encode offer.offerQrUri as a QR code image. For mobile, render offer.offerUri as a tappable link.

What you just received

The result of createOffer is not a credential. It is a wallet handoff for an OpenID4VCI flow: The wallet receives the credential only after it redeems the offer with the issuer.

Track issuance status

For deferred issuance and patching claims after the offer is created, see Deferred issuance.

Next

Credential definitions

Define the credential type and claim paths your business will issue.

Credential offers

Lifecycle, transaction codes, cancellation, and status polling.

Troubleshooting

Fix credential_definition_not_found, invalid_key_format, and other common errors.