Presentation
A doğrulayıcı (verifier)Gösterilen belgeyi denetleyen taraf: imza, belge verenin güven listesindeki kaydı, durum ve politika. Relying party diye de anılır. (a website, an employer, a gate) asks the wallet for a credential; the person approves; the verifier computes the result locally, without asking the source. The protocol is OpenID4VP (OpenID for Verifiable Presentations)Doğrulayıcının cüzdandan belge istediği ve gösterimi aldığı protokol. 1.0 (the EU profile HAIP (High Assurance Interoperability Profile)Yüksek güvenceli kullanım için OpenID4VC seçeneklerini sabitleyen profil; EUDI Wallet'ta da kullanılır. 1.0) and the query language is DCQL (Digital Credentials Query Language)Doğrulayıcının OpenID4VP'de hangi belgeleri ve hangi alanları istediğini yazdığı sorgu dili..
The request
- The request is signed. The verifier is identified by the fingerprint of its erişim sertifikası (access certificate)Relying party'nin isteklerini imzaladığı X.509 sertifikası; client kimliği bu sertifikanın özetinden türetilir. (client_id = x509_hash:…HAIP'teki client kimliği biçimi: kimlik, relying party'nin erişim sertifikasının base64url SHA-256 özetidir.); the wallet checks the signature, the certificate and the verifier's entry in the güven listesi (trust list)Bir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir., and shows the person the registered purpose and the requested fields.
- A verifier may only ask for fields within the scope of its entry in the trust list.
- The response is encrypted with the verifier's key.
Channels
| Channel | When |
|---|---|
QR code / link (openid4vp://) | a website or kiosk on another device |
| Digital Credentials API | a website in the browser on the same phone (the browser opens the wallet) |
| ISO 18013-5 proximity (BLE) | a gate, turnstile or counter — in person |
Verification and three outcomes
The verifier checks, in order, the signature, the issuer's authorisation in the trust list, the holder bindingBelgeyi yalnız belge sahibinin cihazındaki bir anahtara bağlamak; kopyalanan belge gösterilemez., the validity period and the revocation status. The result has three values:
| Outcome | Meaning |
|---|---|
ACCEPTED | the credential is valid |
REJECTED | the credential is invalid; the failing step is reported |
INDETERMINATE | cannot be verified right now (e.g. the status list is stale) — it does not mean the credential is bad |
import { verifyPresentation } from "@tamga-network/verifier";
const { result, claims } = await verifyPresentation({
presentation, aud, nonce, policy, policyCredentialId: "diploma", trust, statusCache, // full example: Code examples
});
if (result.outcome === "ACCEPTED") {
// claims: only the fields the policy asked for. Log field names only, never values.
}Your own server or the hosted one?
- Tamga Verify (
verify.tamga.network): the hosted verifier and page kit; the result is given only to your server, and only once. Guide: GUIDE-0001. - Your own server:
@tamga-network/verifier. Guide: GUIDE-0002.
Details
- Protocol: SPEC-PROTO-0002, verification pipeline: SPEC-API-0001