Skip to content

Issuance ​

The institution (the belge veren (issuer)Belgeyi imzalayıp veren kurum: üniversite, meslek kuruluşu, kamu kurumu ya da şirket.) issues a credential to the person's wallet with OpenID4VCI (OpenID for Verifiable Credential Issuance)Belge verenin belgeyi cüzdana teslim ettiği protokol. 1.0 (the EU profile HAIP (High Assurance Interoperability Profile)Yüksek güvenceli kullanım için OpenID4VC seçeneklerini sabitleyen profil; EUDI Wallet'ta da kullanılır. 1.0). There are two ways to start.

The institution creates a credential offer; the person scans the QR code with the wallet or taps the link. The offer is standard (openid-credential-offer://). An optional one-time code (tx_code) is never sent over the same channel as the offer.

2. The person asks from the wallet ​

In the wallet the person picks their university from the list of institutions and asks for the credential. The institution knows that the requester really is that person because the verified identity in the wallet is presented; there is no matching by name or number. The credential data is read from the institution's own system (the yetkili kaynak (authentic source)Belgedeki bilginin asıl sahibi olan sistem; örneğin üniversitenin öğrenci bilgi sistemi.) at the moment of signing; Tamga keeps no register of people.

Wallet attestations ​

When receiving a credential, the wallet presents a short-lived WIA (Wallet Instance Attestation)Cüzdan sağlayıcısının imzaladığı, cüzdan kurulumunun gerçek olduğunu bildiren kısa ömürlü beyan; belge veren, belgeyi vermeden önce denetler. signed by the cüzdan sağlayıcısı (wallet provider)Cüzdanı sunan ve cüzdan ile anahtar kanıtlarını imzalayan kuruluş. Tamga Wallet ağın ilk cüzdanıdır. that built it, and a key attestationCüzdan sağlayıcısının, belge anahtarının güvenli donanımda üretildiğini ve tutulduğunu bildiren kısa ömürlü beyanı. showing that its keys are kept in secure hardware. The institution checks them against the wallet providers in the güven listesi (trust list)Bir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir.; no credential is issued to a wallet from a provider that is not on the list.

The flow at a glance ​

wallet                         institution (issuer.tamga.network/{institution})
  │  metadata  ───────────────▶  /.well-known/openid-credential-issuer/{institution}
  │  PAR + authorisation (DPoP) ▶  identity matching / offer code
  │  token  ──────────────────▶  wallet attestation check
  │  credential (proof) ──────▶  signature; entry in the status list
  │  ◀───────────────────────  SD-JWT VC (+ mdoc for identity), batch copies

Your own service or the hosted one? ​

  • Hosted service: issuer.tamga.network/{institution}; your institution creates offers from its own systems with an API key and manages credentials in the Institution Console. Guide: GUIDE-0003.
  • Your own service: with @tamga-network/issuer; you register in the trust list as an issuer.

Details ​