Skip to content
GUIDE-0000GuideIn forceversion 1.0.13 October 2026

Get started ​

This page is the first stop for anyone who wants to build something with Tamga: it shows which path fits you, which package to install and how to try things locally.

When to read: on day one, before writing any code. From here you move on to the guide for your role. If you would like a look at the ideas first, the Concepts section is short and plain.

What does Tamga do? ​

Institutions issue credentials to people: a diploma, a student certificate, an identity credential, a ticket. Tamga puts these credentials into the wallet on the person's phone. Anyone who needs to see one (an employer, a website, an event gate) verifies it in seconds, without asking the institution. Each time, the person shares only the fields that were asked for.

The standards are the same as the EU digital identity wallet: SD-JWT VC (Selective Disclosure JWT Verifiable Credential)Selective disclosure destekli JSON tabanlı belge biçimi; EUDI Wallet'ta ve Tamga'da çevrimiçi gösterme için kullanılır. and ISO mdocISO/IEC 18013-5 mobil belge biçimi, CBOR ile kodlanır; yüz yüze gösterme ve mobil ehliyet için kullanılır.credentialsBelge verenin imzaladığı ve kişinin cüzdanında duran dijital belge; kişi yalnız istenen alanları gösterir., OpenID4VCI (OpenID for Verifiable Credential Issuance)Belge verenin belgeyi cüzdana teslim ettiği protokol. for issuance, OpenID4VP (OpenID for Verifiable Presentations)Doğrulayıcının cüzdandan belge istediği ve gösterimi aldığı protokol. for presentation, X.509 for institutional identity, and signed trust listsBir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir..

This site is for developers. Roles, rules and the conditions for taking part are in Tamga ARF; the general overview is at tamga.network.

Which path is yours? ​

What do you want to do?GuidePackage
Add "Sign in with Tamga" to your websiteGUIDE-0001@tamga-network/verifier (+ /web)
Verify credentials on your server (hiring, campus, age, ticket gate)GUIDE-0002@tamga-network/verifier, @tamga-network/trust
Register your institution as an issuerGUIDE-0007—
Register your site as a verifierGUIDE-0008—
Issue your institution's credentials to people's walletsGUIDE-0003@tamga-network/issuer (+ /client)
Build a Tamga-compatible walletGUIDE-0005, checklist GUIDE-0010@tamga-network/wallet-core
Read trust lists, and later run a network nodeGUIDE-0006@tamga-network/trust, contracts/, network/
Connect your country's trust list to the networkGUIDE-0011apps/trust-publisher
Show that your application follows the rulesGUIDE-0009conformance/
Test end to end without touching the real network (test network)GUIDE-0013sandbox.tamga.network
See working, tested code for all of the aboveGUIDE-0004—
When something goes wrongGUIDE-0012—

Try it locally ​

You need Node.js 22 and Git. Clone the repository and set up the development environment:

sh
git clone https://github.com/tamga-network/tamga-network && cd tamga-network
npm install
npm run setup            # development PKI → schema catalogue → trust lists → verification
npm run check            # tests + type check
npx vitest run examples   # four examples, with the real packages

npm run setup produces a local root certificate, sample institution certificates and signed trust lists (ops/pki/; private keys never enter the repository). You can test your code against these local lists. For the conformance vectors: npm run conformance (conformance/).

Packages ​

PackageWhat it doesWho uses it
@tamga-network/coredigests, identifier derivation (issuer_id, schema_id), certificate helperseveryone (indirectly)
@tamga-network/trust (+ /core)loads and verifies the signed trust lists; one read interface, TrustSourceverifier, wallet, issuer
@tamga-network/schemascredential type catalogue: type metadata, JSON Schema, integrity digestsissuer, verifier
@tamga-network/sd-jwtSD-JWT VC: selective disclosure, holder binding, status listissuer, verifier
@tamga-network/mdocISO 18013-5 mdoc: CBOR, COSE, issuance and verificationidentity issuer, verifier
@tamga-network/issuer (+ /client)credential creation, OpenID4VCI; /client for the hosted serviceissuer
@tamga-network/verifier (+ /web, /zk)verification pipeline, three-valued result, OpenID4VP; /web page kit, /zk zero-knowledge proofsverifier, website
@tamga-network/wallet-corewallet core: keys, receiving credentials, local checks, presentation (Node + React Native)wallet developer

Every package has its own page in the SDKs section. The packages are published on npm as a pre-release (0.x); interfaces may change before 1.0. Each release is built from this repository by GitHub Actions and carries provenance.

Addresses ​

AddressWhatWho uses it
https://trust.tamga.networksigned trust lists (lotl.jws, tl-tr.jws), anchor log, keys/everyone — through TrustSource
https://tamga.network/trust-anchorroot fingerprints (you pin them in your configuration)everyone
https://schemas.tamga.network/v1/catalogue.jsoncredential type catalogueissuer, verifier, wallet
https://issuer.tamga.network/{institution}hosted issuer service (OpenID4VCI + /api/v1)issuer, wallet
https://status.tamga.network/{opaque}status lists (Token Status List)verifier
https://verify.tamga.networkTamga Verify: hosted verifier + page kit (/tamga-verifier.js)website, verifier
https://wallet.tamga.networkwallet provider: Wallet Instance Attestation (WIA)wallet
https://id.tamga.networkprovisional identity credential servicewallet

What is ready today? ​

PartStatus
Packagespre-release on npm (0.x); interfaces may change before 1.0
Hosted verifierrunning: the website's server opens the presentation with a signed statement, and the values are given only to it, only once (ADR-0017); policies are fixed for now
Hosted issuerrunning: a scoped API key per institution (ADR-0016)
Trust anchorsigned trust lists (ADR-0009); the Tamga operator registers issuers and verifiers
Privacya pseudonym per site (ADR-0031); age verification with a zero-knowledge proof (ZK) — the verifier side is ready (ADR-0032)
Ledger (Besu/QBFT)designed, contracts written; opens once there are at least two independent validator operators (GUIDE-0006)

Rules for every integration ​

  • Do not log personal data. Credential field values and the status index never go into logs or audit records (SPEC-API-0001 AP3–AP4).
  • Ask only for the fields you need. Your request cannot go beyond the scope of your trust list entry (AP6).
  • The result has three values: ACCEPTED, REJECTED, INDETERMINATE. "Cannot be verified right now" does not mean the credential is bad (AP2).
  • Read trust data only through TrustSource; do not interpret the list files yourself.
  • All the binding rules for your role: Tamga ARF — Annex B, Tamga Rulebook.