How Tamga works
Tamga and the EUDI architecture
Tamga keeps the EU’s technical layer as it is and writes its own governance layer for the Turkic world. This page shows, row by row, where Tamga is the same, where it builds a bridge, what is planned — and what it does differently on purpose.
The same layers
The EU framework has five layers. Tamga mirrors each one with its own document set.
| Layer | EU | Tamga |
|---|---|---|
| Law and governance | eIDAS 2.0 + implementing acts | Tamga Trust Framework |
| Architecture and roles | ARF | Tamga ARF |
| Participant rules | ARF high-level requirements | Tamga Rulebook |
| Document-type rules | Attestation rulebooks | Education rulebook, more to follow |
| Technical standards | ETSI · IETF · OpenID · ISO | the same, with Tamga profiles |
Roles: who does what, today and later
Every role of the EU architecture exists in Tamga. Where a state has not joined yet, Tamga holds the role provisionally — on the record, on behalf of the state.
| Role (ARF) | Today | When the state joins |
|---|---|---|
| Trusted List Operator | Tamga — provisional, on behalf of the national authority | the national authority |
| Registrar | Tamga (on behalf) | the state registrar |
| National Root CA | “TR National Root CA (provisional operator: Tamga)” — its identifier does not change on handover | the state’s own root |
| PID Provider | empty slot; an identity credential from Tamga’s identity service (document + liveness check) instead | the state |
| Attestation Provider | universities, ticket sellers | + public bodies |
| Wallet Provider | Tamga (wallet attestation) | + certified third parties |
| Relying Party | employers, websites, gates — registered with a scope | the same |
| Validator Operator | none — no ledger in this phase | ≥ 2 independent operators → ledger |
Standards
The technical layer is the same. Where the first release still takes a shortcut, the row says so.
● same · ◐ bridge (same model, interim form) · ○ planned
| Component | EU | Tamga | Fit |
|---|---|---|---|
| Trust lists | ETSI TS 119 612 | same model, signed JSON (JWS); ETSI XML projection planned | bridge |
| Institution identity | X.509 | X.509, national root | same |
| Credential format | SD-JWT VC | SD-JWT VC (dc+sd-jwt), ES256 | same |
| Mobile document | ISO/IEC 18013-5 mdoc | identity credential also issued as mdoc | same |
| Issuance | OpenID4VCI 1.0 | OpenID4VCI: pre-authorized code + PIN, or wallet-initiated | same |
| Presentation | OpenID4VP 1.0, DCQL | OpenID4VP, DCQL, signed request, encrypted answer | same |
| Revocation | IETF Token Status List | same, published at a fixed interval | same |
| Identity proofing | ETSI TS 119 461 | document + liveness check, mapped to assurance levels | same |
| Wallet attestation | Wallet Unit Attestation | WUA required by issuers; until Tamga Wallet is on the App Store and Google Play, the phone’s own claim of secure hardware is not accepted (every wallet counts as software-level); with the store release App Attest / Play Integrity become mandatory | bridge |
| Key storage | secure element (WSCD) | first release: software keys; pilot: the phone’s secure enclave | bridge |
| Close range | ISO 18013-5 over NFC/BLE | QR pass for gates today; NFC/BLE next | bridge |
| Browser | W3C Digital Credentials API | planned | planned |
| Qualified e-signature | QES from the wallet | planned | planned |
Where Tamga differs on purpose
| Difference | What it means |
|---|---|
| by designSovereignty-first governance | Each state is the only writer of its own registry; network membership by a 2/3 vote; cross-border recognition decided by each state unilaterally. |
| by designProvisional operator, built for handover | No structure assumes Tamga as the only operator. Every member state has a slot; handover changes only the operator field. |
| by designOptional ledger | The EU relies on lists alone. Tamga adds a permissioned ledger only when at least two independent operators join; lists and ledger give the same answers. |
| by designPublic anchor log | Every revocation-list publication and schema change is a signed line in an append-only log, at least hourly — a rolled-back list is detectable. |
| by designThree outcomes, always | “Could not check” (INDETERMINATE) is never reported as “rejected”. |
| by designNo national ID in shared documents | The national ID number appears only in the identity credential; diplomas, tickets and cards never carry it. |
Known limits, stated openly
These limits are also listed in the pilot’s limitations notice.
- In this phase the trust anchor rests on one operator’s signature; the public log, transparency report and audits deter misuse but cannot make it impossible.
- A revocation takes effect within about 90 minutes at most.
- The same issuer could link a person across verifiers if they collude; closing this needs zero-knowledge credentials.
- First release only: keys in software and the issuer key held by Tamga — both close before the pilot.
Details: trust lists · architecture · eIDAS, EUDI and EBSI.