Skip to content

Institution Source Endpoint ​

The lookup endpoint an institution exposes so that the hosted issuer can read credential data at issuance time.

Example — you choose the URL; it is configured for your institution on the hosted issuer.
https://sis.example.edu/tamga
Authentication
Bearer (tamga-source-request+jwt)
Definition
OpenAPI 3.1 file · Guide

Implemented by the institution, not by Tamga (ADR-0020, authentic source at the institution). Tamga's hosted issuer calls it and never stores the response. Two operations share one URL and are selected by the op claim of the signed request:

  • lookup — the person started the request from the wallet and presented a Tamga identity attestation. Tamga sends the matching keys (national identification number + date of birth). Return the matching subject or 404.
  • fetch — Tamga already knows your opaque subject reference (identity-bound offer, credential issuance, credential refresh). Return the current record or 404 (the person is no longer in your records).

Privacy. Return only the fields needed for the requested vct. Do not log the matching keys. Errors other than 404 make Tamga answer the wallet with temporarily_unavailable; no credential is issued.

Endpoints ​

EndpointDescription
POST /Look up or fetch a subject record

Authentication ​

Bearer (tamga-source-request+jwt)

Not a header: the body carries a short-lived JWT (typ: tamga-source-request+jwt, ES256, lifetime 60 s) signed with the access key Tamga uses for your institution. Verify it with the certificate in the x5c header and check that this certificate is listed for Tamga's hosted issuer in the Tamga signed trust list; check that aud equals your endpoint URL, check exp, and reject a repeated jti. Serve only over TLS.

Source ​

The single operation.

Look up or fetch a subject record ​

POST/

The body carries a signed request; its payload is SourceRequestClaims (below).

Authentication Bearer (tamga-source-request+jwt)

Request body ​

application/json

FieldTypeDescription
request requiredstringCompact JWS; payload is SourceRequestClaims.

Responses ​

StatusDescription
200Record found.
401Request signature, audience, lifetime or replay check failed.
404No matching record. Body may be {"subject": null}.
503Temporarily unavailable. Tamga issues nothing and the person retries later.

Example ​

bash
curl -X POST "https://sis.example.edu/tamga/" \
  -H "Content-Type: application/json" \
  -d '{"request":"eyJhbGciOiJFUzI1NiIsInR5cCI6InRhbWdhLXNvdXJjZS1yZXF1ZXN0K2p3dCIsIng1YyI6WyIuLi4iXX0.eyJvcCI6ImZldGNoIn0.sig"}'
json
{
  "subject": {
    "id": "…",
    "student_no": "…",
    "family_name": "…",
    "given_name": "…",
    "birth_date": "2026-10-09",
    "programme_title_tr": "…",
    "study_level": 0,
    "enrollment_year": 0,
    "student_status": "ACTIVE"
  }
}

Objects ​

SourceRequestClaims ​

Payload of the signed request.

FieldTypeDescription
op requiredstringOne of: lookup · fetch
iss requiredstringThe hosted issuer's client identifier — x509_hash: + base64url(SHA-256(its access certificate)) (HAIP 1.0).
aud requiredstringYour endpoint URL.
iat requiredinteger
exp requiredintegeriat + 60
jti requiredstring
vct requiredstringCredential type being issued, e.g. urn:tamga:edu:DiplomaCredential:1.
matchobjectPresent when op = lookup.
match.personal_administrative_number requiredstring
match.birth_date requiredstring (date)
subject_refstringPresent when op = fetch. Your opaque identifier returned earlier as SubjectRecord.id.

SubjectRecord ​

Education profile (student and diploma credentials). id is your opaque, stable subject reference; Tamga keeps only this value (for revocation and refresh). Other profiles are added per credential type.

FieldTypeDescription
id requiredstring
student_no requiredstring
family_name requiredstring
given_name requiredstring
birth_date requiredstring (date)
personal_administrative_numberstringOptional; used only for matching, never written into education credentials.
programme_title_tr requiredstring
programme_title_enstring
faculty_trstring
isced_f_codestring | null
study_level requiredintegerEQF/ISCED level
enrollment_year requiredinteger
student_status requiredstringOne of: ACTIVE · ON_LEAVE
expected_graduation_yearinteger
programme_credit_pointsnumberProgramme workload in ECTS (EU proof of enrolment, EUHEPOE). Optional.
enrollment_datestring (date)Date of enrolment (EU proof of enrolment, EUHEPOE). Optional; enrollment_year stays required.
graduateobjectPresent only for graduates; required for DiplomaCredential.
graduate.qualification_tr requiredstring
graduate.qualification_enstring
graduate.eqf_level requiredinteger
graduate.awarding_date requiredstring (date)
graduate.gradestring
graduate.thesis_title_trstring
graduate.mode_of_studystringOne of: FULL_TIME · PART_TIME · DISTANCE · BLENDED

Import the machine-readable definition into any OpenAPI tool to generate a client or send test requests: institution-source.openapi.yaml.