bindsTo
True when this credential's challenge demands the same payment (realm/method/intent/request) as the server-issued expected challenge. Deliberately ignores per-issuance fields (id/expires/opaque/description), which the verifier binds instead.