Chapter 2 · 4/8
Verifiable credentials
What a verifiable credential is, what it contains and how it differs from a paper document.
5 min
We have seen hashes, keys, signatures and certificates. Now we reach the thing that brings them all together: the A digital document in which an institution signs information about a person and gives it to the person's wallet.. A diploma, a student certificate, a ticket, a professional licence, an identity credential: all can be issued this way.
What is inside?
- Issuer: which institution issued it (and its certificate).
- Type: whether it is a diploma or a ticket. In Tamga each type has a permanent name and rules.
- Claims: the actual content, such as name, programme, graduation date or seat number.
- Validity: when it was issued and until when it is valid.
- Status pointer: where to find out whether it has been revoked.
- Binding to the person: the wallet key the credential is bound to.
- Signature:the institution's digital signature over all of it.
Bound to the person: a credential that cannot be copied
Anyone can copy a PDF and forward it. A verifiable credential is bound, at issuance, to a key on the person's phone. When the credential is presented, the wallet signs one more small proof with that key: Binding a credential to a key in the wallet, so that only the wallet holding that key can present it.. Even if a copy of the credential reaches someone else, it cannot be presented without that key.
How it differs from paper
- Software checks it, not a person; it takes seconds.
- A forged credential fails the signature check.
- Claims can be shown one by one; there is no need to hand over the whole document.
- When it is revoked, the verifier finds out immediately.
Summary
- A verifiable credential holds issuer, type, claims, validity, status pointer, binding and signature.
- It is bound to the person's wallet key; a copy is useless to anyone else.
- Shared credential types mean it is read the same way in every country.
Go deeper
Technical details and binding rules: