Chapter 7 · 1/5
Issuing as an institution
The steps an institution takes to issue credentials on the network, and what it needs.
6 min
A university wants to issue its graduation certificate digitally, a professional chamber its membership card, a concert promoter its tickets. To do this on Tamga Network, the institution first registers with the network. Registration tells every verifier on the network: "This institution is real, this key belongs to it, and it may issue this type of credential."
This page walks through the path in plain words. The forms and technical steps are in the developer docs and Tamga ARF.
What you need before you start
- A legal entity and an authorised person.The institution's official registration and confirmation of someone who can sign on its behalf.
- A domain name.The institution's own web address. The network checks that it really belongs to the institution.
- The source of the data.For a diploma, the student information system; for membership, the chamber's register. The network calls this the authentic sourceThe place where the original record behind a credential is kept; data is read from there when issuing.. Data is not copied into the network; it is read from the source at the moment of issuing.
- A credential type. What you issue must be defined in advance: the Education Rulebook describes the student certificate and the diploma, the Event Ticket Rulebook the event ticket. A new type first gets its own rules.
- A data protection set-up. Who you issue to, and how, must follow data protection law.
Step by step
- Application.The institution provides the same data the EU's common registration data set asks for: official name, registration number, address, contact and what it will do.
- Gate checks. Domain ownership, contact details and legal identity are checked. No registration without passing the gate.
- Certificate. The institution creates a key pair. The private key stays with the institution; a certificateA signed digital ID card that proves who a public key belongs to. is issued for the public key. Verifiers check the signature on a credential against it.
- Credential type permission. Each type is granted separately; none is open by default. A university may issue diplomas, but not tickets.
- Trial and conformance tests.The institution produces trial credentials against the network's public test vectors; the report goes with the application.
- Entry into the list.The institution is added to its country's trust listA signed, public list showing which institutions may issue which credentials.. From then on every verifier recognises it.
- First credential.The institution either connects the network's hosted issuing service to its system or runs its own software with the open-source packages. Either way, the credential goes to the compatible wallet the person chooses.
How long does it take? That depends on the institution: a ready data source, the agreement and the tests.
Assurance levels
Not every institution is checked to the same depth. The verifier sees which level a credential comes from and decides accordingly.
- Registered:domain and contact verified, trial credentials passed the tests. Shown to verifiers as "not accredited".
- Contracted: legal entity, authorised signatory, participation agreement and institution certificate in place.
- Accredited: keys in secure hardware, audit and record-keeping duties, incident reporting and an annual review.
- Public:a state body or an authentic source; registered by that state's registrar.
After joining
An institution always remains subject to the network's rules. If something goes wrong it can be suspended: it can no longer issue, but credentials it issued earlier stay valid as of their issue date. An institution can also leave with notice; past records are not deleted and old credentials keep verifying.
Summary
- The institution registers; its domain, legal identity and key are checked, and the private key stays with it.
- Each credential type is granted separately; an institution that passes the tests enters its country's trust list.
- Suspension or exit does not invalidate earlier credentials; the process is the same for everyone.
Go deeper
Technical details and binding rules: