Chapter 7 · 3/5
Building a wallet
Becoming a wallet provider, passing the conformance tests and getting onto the network's list.
6 min
Tamga Network does not pick wallets; it recognises them. A bank, a start-up, a public body or a community can build its own wallet; any wallet that follows the network's published rules and passes the tests works on the network. The organisation that builds and runs a wallet is a wallet providerThe organisation that builds and runs the wallet app and vouches that its wallets are genuine..
What a wallet must do
- Protect keys.The key bound to a person's credential never leaves the phone; it is kept in secure hardware and unlocked with a PIN or biometrics.
- Ask the person. Nothing leaves without consent. The consent screen clearly shows who is asking, what for and why.
- Keep the record with the person. What was shown to whom is stored only on the phone; the person can export it encrypted or delete it.
- Protect privacy. Selective disclosure, a separate copy per verifier and a pseudonym per site are supported.
- Prove itself. When receiving a credential, the wallet shows it is a genuine, unmodified wallet with two proofs: a Wallet Instance AttestationThe wallet provider's signed statement that this wallet is its genuine app. and a key attestationA signed statement that the credential key was created in and is kept by secure hardware. saying the key is in secure hardware.
Step by step
- Read the rules. The wallet rules in the Tamga Rulebook and the wallet specification say, in numbered items, what a wallet must do.
- Build.You may use the open-source wallet core; you don't have to. Any software that follows the specification is valid. While building you can work with the network's trial wallet provider.
- Declare your wallet solution. Which platforms, which level of secure hardware, which unlock method and which backup model.
- Pass the conformance tests. Key protection, the consent screen, history and deletion, both proofs and the presentation protocol; plus a demonstration on a real device.
- Enter the list. The key you sign both proofs with is added to the list of trusted lists. From then on, institutions on the network can issue credentials to your wallet.
How long does it take? That depends on the team and the test results.
Summary
- The network recognises wallets rather than picking them: any wallet that follows the rules and passes the tests works.
- A wallet keeps keys in secure hardware, sends nothing without consent and leaves the record with the person.
- A provider that passes has its signing key added to the list of trusted lists; Tamga Wallet takes the same path.
- Testing happens on a separate test network (the sandbox): made-up people, its own trust root and, to keep it realistic, example institutions under real names (İstanbul Bilgi Üniversitesi, Bubilet, Paribu Cineverse — there is no relationship or agreement with them); a credential from there is signed with a test key and is not valid anywhere.
Go deeper
Technical details and binding rules: