Get started
This page is the first stop for anyone who wants to build something with Tamga: it shows which path fits you, which package to install and how to try things locally.
When to read: on day one, before writing any code. From here you move on to the guide for your role. If you would like a look at the ideas first, the Concepts section is short and plain.
What does Tamga do?
Institutions issue credentials to people: a diploma, a student certificate, an identity credential, a ticket. Tamga puts these credentials into the wallet on the person's phone. Anyone who needs to see one (an employer, a website, an event gate) verifies it in seconds, without asking the institution. Each time, the person shares only the fields that were asked for.
The standards are the same as the EU digital identity wallet: SD-JWT VC (Selective Disclosure JWT Verifiable Credential)Selective disclosure destekli JSON tabanlı belge biçimi; EUDI Wallet'ta ve Tamga'da çevrimiçi gösterme için kullanılır. and ISO mdocISO/IEC 18013-5 mobil belge biçimi, CBOR ile kodlanır; yüz yüze gösterme ve mobil ehliyet için kullanılır.credentialsBelge verenin imzaladığı ve kişinin cüzdanında duran dijital belge; kişi yalnız istenen alanları gösterir., OpenID4VCI (OpenID for Verifiable Credential Issuance)Belge verenin belgeyi cüzdana teslim ettiği protokol. for issuance, OpenID4VP (OpenID for Verifiable Presentations)Doğrulayıcının cüzdandan belge istediği ve gösterimi aldığı protokol. for presentation, X.509 for institutional identity, and signed trust listsBir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir..
This site is for developers. Roles, rules and the conditions for taking part are in Tamga ARF; the general overview is at tamga.network.
Which path is yours?
| What do you want to do? | Guide | Package |
|---|---|---|
| Add "Sign in with Tamga" to your website | GUIDE-0001 | @tamga-network/verifier (+ /web) |
| Verify credentials on your server (hiring, campus, age, ticket gate) | GUIDE-0002 | @tamga-network/verifier, @tamga-network/trust |
| Register your institution as an issuer | GUIDE-0007 | — |
| Register your site as a verifier | GUIDE-0008 | — |
| Issue your institution's credentials to people's wallets | GUIDE-0003 | @tamga-network/issuer (+ /client) |
| Build a Tamga-compatible wallet | GUIDE-0005, checklist GUIDE-0010 | @tamga-network/wallet-core |
| Read trust lists, and later run a network node | GUIDE-0006 | @tamga-network/trust, contracts/, network/ |
| Connect your country's trust list to the network | GUIDE-0011 | apps/trust-publisher |
| Show that your application follows the rules | GUIDE-0009 | conformance/ |
| Test end to end without touching the real network (test network) | GUIDE-0013 | sandbox.tamga.network |
| See working, tested code for all of the above | GUIDE-0004 | — |
| When something goes wrong | GUIDE-0012 | — |
Try it locally
You need Node.js 22 and Git. Clone the repository and set up the development environment:
git clone https://github.com/tamga-network/tamga-network && cd tamga-network
npm install
npm run setup # development PKI → schema catalogue → trust lists → verification
npm run check # tests + type check
npx vitest run examples # four examples, with the real packagesnpm run setup produces a local root certificate, sample institution certificates and signed trust lists (ops/pki/; private keys never enter the repository). You can test your code against these local lists. For the conformance vectors: npm run conformance (conformance/).
Packages
| Package | What it does | Who uses it |
|---|---|---|
@tamga-network/core | digests, identifier derivation (issuer_id, schema_id), certificate helpers | everyone (indirectly) |
@tamga-network/trust (+ /core) | loads and verifies the signed trust lists; one read interface, TrustSource | verifier, wallet, issuer |
@tamga-network/schemas | credential type catalogue: type metadata, JSON Schema, integrity digests | issuer, verifier |
@tamga-network/sd-jwt | SD-JWT VC: selective disclosure, holder binding, status list | issuer, verifier |
@tamga-network/mdoc | ISO 18013-5 mdoc: CBOR, COSE, issuance and verification | identity issuer, verifier |
@tamga-network/issuer (+ /client) | credential creation, OpenID4VCI; /client for the hosted service | issuer |
@tamga-network/verifier (+ /web, /zk) | verification pipeline, three-valued result, OpenID4VP; /web page kit, /zk zero-knowledge proofs | verifier, website |
@tamga-network/wallet-core | wallet core: keys, receiving credentials, local checks, presentation (Node + React Native) | wallet developer |
Every package has its own page in the SDKs section. The packages are published on npm as a pre-release (0.x); interfaces may change before 1.0. Each release is built from this repository by GitHub Actions and carries provenance.
Addresses
| Address | What | Who uses it |
|---|---|---|
https://trust.tamga.network | signed trust lists (lotl.jws, tl-tr.jws), anchor log, keys/ | everyone — through TrustSource |
https://tamga.network/trust-anchor | root fingerprints (you pin them in your configuration) | everyone |
https://schemas.tamga.network/v1/catalogue.json | credential type catalogue | issuer, verifier, wallet |
https://issuer.tamga.network/{institution} | hosted issuer service (OpenID4VCI + /api/v1) | issuer, wallet |
https://status.tamga.network/{opaque} | status lists (Token Status List) | verifier |
https://verify.tamga.network | Tamga Verify: hosted verifier + page kit (/tamga-verifier.js) | website, verifier |
https://wallet.tamga.network | wallet provider: Wallet Instance Attestation (WIA) | wallet |
https://id.tamga.network | provisional identity credential service | wallet |
What is ready today?
| Part | Status |
|---|---|
| Packages | pre-release on npm (0.x); interfaces may change before 1.0 |
| Hosted verifier | running: the website's server opens the presentation with a signed statement, and the values are given only to it, only once (ADR-0017); policies are fixed for now |
| Hosted issuer | running: a scoped API key per institution (ADR-0016) |
| Trust anchor | signed trust lists (ADR-0009); the Tamga operator registers issuers and verifiers |
| Privacy | a pseudonym per site (ADR-0031); age verification with a zero-knowledge proof (ZK) — the verifier side is ready (ADR-0032) |
| Ledger (Besu/QBFT) | designed, contracts written; opens once there are at least two independent validator operators (GUIDE-0006) |
Rules for every integration
- Do not log personal data. Credential field values and the status index never go into logs or audit records (SPEC-API-0001 AP3–AP4).
- Ask only for the fields you need. Your request cannot go beyond the scope of your trust list entry (AP6).
- The result has three values:
ACCEPTED,REJECTED,INDETERMINATE. "Cannot be verified right now" does not mean the credential is bad (AP2). - Read trust data only through
TrustSource; do not interpret the list files yourself. - All the binding rules for your role: Tamga ARF — Annex B, Tamga Rulebook.