Following up @gabrielhof, the signing and response from the issuer should allow us to trust the response and there are certain required constraints in the content of the response. Can you share a detailed example of the metadata and response so we can better formulate a solution together? Thanks in advance!