How Tamga works

Trust lists: who may issue what

A signature proves who signed a document. It does not prove that the signer is a real university. That second question is answered by a trust list — a signed public register of institutions, their certificates, what they may issue and their current status.

What is in a trust list

  • Root certificate authorities of each state, with their status.
  • Issuers — universities, public bodies, ticket sellers — with their certificate fingerprint, category and assurance class, and the document types they are authorized for, each with a time window.
  • Relying parties (verifiers) with the fields they may request. Your wallet compares every request with this scope and warns if a verifier asks for more.
  • Wallet providers whose attestation keys vouch for genuine wallet apps.
  • The document-type catalogue: each type’s metadata address and content hash.

There is no personal data in a trust list — only institutions, certificates, statuses, dates and addresses.

Why you can trust the list itself

  • Signed. Every list is a signed JWS; verifiers use only the signed file and check the signer against a fixed root fingerprint published out of band.
  • Versioned and hash-chained. Each version carries the hash of the previous one. Nothing is deleted; status changes are appended to a history.
  • Always fresh. Every list carries a “next update” date; a stale list is not trusted.
  • Anchor log. Every status-list publication and schema change is written as a signed line to a public, append-only log, at least hourly. A verifier can detect a list that was rolled back or rewritten.
Published files
https://trust.tamga.network/
  lotl.jws                    list of lists: national lists, schemas, wallet providers
  tl-tr.jws                   Türkiye: root CAs, issuers, relying parties
  tl-az.jws · tl-kz.jws …     reserved slots for the other member states
  anchors.jsonl               anchor log: one signed line per event, at least hourly
  keys/root-fingerprints.json the root of trust (also at tamga.network/trust-anchor)
  archive/                    every past version, never deleted

How a verifier uses it

Credential

signed by an institution

Trust list

authorized on the issue date?

Status list

revoked or suspended?

Result

accepted · rejected · indeterminate

Authorization is checked against the date the credential was issued. A diploma issued while the university was active stays valid even if the university is later suspended; new issuance stops at once. If the list cannot be reached or is out of date, the answer is indeterminate — never a false “rejected”.

Built for many states from day one

The structure already has a slot for every member state of the Organization of Turkic States. Today Tamga signs the lists as a provisional operator, on behalf of the states. Handing over changes only the operator field — institution identifiers, document types and existing credentials stay the same.

From lists to a ledger

Trust lists are what the EU itself uses (ETSI TS 119 612, the EUDI trusted lists). Every field maps to a smart-contract record, so the same data can later move to a permissioned ledger — once at least two independent operators join. The list history is then replayed and both are tested to give the same answer.