Skip to content

Annex C — Attestation Rulebook: Tamga Identity Attestation ​

Document FW-RB-0003 · Version 0.1.1 · Status Draft · Updated 2026-09-27 · Licence CC BY 4.0 Official English translation of the Turkish source text; in case of conflict the Turkish text prevails.

Draft

This rulebook is a draft awaiting approval. It compiles rules that are already in force (ADR-0011, ADR-0013, SPEC-ID-0003, FW-RB-0001 RB-AP-ID); it becomes Active once approved.

The attestation rulebook for the identity document Tamga issues as the provisional identity attestation provider (urn:tamga:id:IdentityAttestation:1): who issues it, with which identity proofing, which fields and which selective-disclosure rule; validity and revocation; the two formats (SD-JWT VC + ISO 18013-5 mdoc); rules for institutions and verifiers; hand-over to a state PID provider. Written on the pattern of the EUDI ARF PID Rulebook — this document is not a PID but an EAA.

0. Scope and status ​

Typevctschema_idCatalogue
Tamga Identity Attestationurn:tamga:id:IdentityAttestation:1keccak256(vct)schemas.tamga.network/v1/id/IdentityAttestation/1.0.0
The same document as mdocdocType tamga.id.1—ADR-0013

The technical definition is in SPEC-ID-0003 §9 and the schema catalogue; in a conflict they prevail. This rulebook creates no new rules; it gathers ADR-0011, ADR-0013, SPEC-ID-0003 and the RB-AP-ID rules of FW-RB-0001 in one place, from the point of view of institutions and verifiers.

Status: this document is not a PID. While no state-appointed PID provider exists, it is an EAA that Tamga issues provisionally, in the qualified class (category: urn:tamga:eaa:qualified); pid_providers[] stays empty in the trusted list (SPEC-TRUST-0001/TL8). When a state provider is appointed, new issuance stops and the entry is handed over to the successor (§8).

1. Data model ​

ClaimTypeSelective disclosureNote
given_name, family_namestringalways
birth_datedatealways
nationalityISO 3166-1 alpha-2always
personal_administrative_numberstringalwaysNational identity number; only in this type (IDP10)
document_typeID_CARD | PASSPORT | RESIDENCE_PERMIT | DRIVING_LICENSEalwaysThe document that was verified
document_number_hashsha256-…alwaysKeyed digest of the document number (HMAC-SHA256; key held only by the identity service) — not the number, and not recoverable from the digest
issuing_countryISO 3166-1 alpha-2always
document_chip_verifiedbooleanalwaysWhether the NFC chip was read (a fact, not a level)
verification_methodremote-document-liveness-face | remote-nfc-liveness-face | in-personalways
age_over_18booleanalwaysDerived; for age checks only this field is disclosed
status, category, cnf, vct, iss, iat, exp—neverWire profile

Not included: portrait/photo, address, document images, an assurance-level (LoA) claim (SPEC-PROTO-0001/PR7). All personal fields are selectively disclosable; a verifier may request only the fields in its registered scope.

2. Who issues it ​

RequirementValue
IssuerThe Tamga Network identity service (id.tamga.network) — the only issuer; institutional issuers cannot issue this type
Category / classIDENTITY · QUALIFIED · I3
Schema authorisationOnly in the identity service's entry (allowlist)
KeyThe identity service's issuing key; separate status key (RB-AP-03)
Role"Provisional Identity Attestation Provider" — not a PID Provider (ADR-0011 K1)

3. Identity proofing before issuance ​

PathLevelNote
Remote: document + liveness + face matchT2 (ETSI TS 119 461 Substantial)verification_method: remote-document-liveness-face
Remote + NFC chipT2; document_chip_verified: trueTechnically high; legally T3 = qualified e-signature (IDP7)
In personT2in-person

Rules: identity verification happens only in the identity service; institutional issuers, the wallet and verifiers do not talk to the provider (IDP3). Before verification starts, an information notice is shown and explicit consent is obtained (IDP11). The provider's decision is always confirmed from its decision endpoint; the webhook is only a trigger (IDP5). A provider outage does not lower the level; issuance stops (IDP8).

4. Data protection ​

  • Tamga is the data controller for this data (FW-TF-0001 §3.5).
  • Personal fields are not kept after issuance; the permanent record is only an opaque subject_ref, the document-number hash, validity and status indexes. Document images, selfies, video and raw OCR data are never stored at Tamga (IDP9).
  • A deletion request revokes the document.
  • No second active attestation is issued for the same document number; re-verification revokes the older one (ADR-0011 K6).

5. Validity and revocation ​

TopicRule
Validityexp = issuance + 730 days (≤ 2 years); re-verification after expiry
Status listMandatory (Token Status List)
Reasons for revocationthe person's deletion request, re-verification with the same document, reported loss/theft of the document, wrong issuance
Copies10 copies, each on a different device key; a different copy per verifier (WL5)

6. Two formats: SD-JWT VC and mdoc ​

The same document is issued as SD-JWT VC (primary) and as ISO/IEC 18013-5 mdoc (ADR-0013):

  • Fields, iat/exp and the holder key are identical in both formats (MD1, MD2).
  • The mdoc signature is ES256 and maps to the same trust anchor (MD3); the result is three-valued (MD4).
  • The verifier chooses the format with DCQL; e.g. an age check in a browser asks for age_over_18 only, through mdoc.

7. Presentation and verification rules ​

UseFields requestedRule
Age checkage_over_18No other field is requested
Matching records at an institution (before issuing a document)personal_administrative_number, birth_date, given_name, family_nameThe institutional issuer receives them only within its registered scope and through the full verification pipeline; it does not store or log matching keys (RB-RP-ID-01, IDP10)
"Holds a valid Tamga identity"noneReference policy etkinlik-tamga-kimlik
High-risk transactionper scopeFace matching, if needed, is the RP's responsibility; the document carries no portrait
  • A verifier requesting the identity number must have that field explicitly in its registration; the wallet flags out-of-scope requests (WL8).
  • The result is three-valued; INDETERMINATE is not acceptance.
  • The verifier must see the issuer in the trusted list in the IDENTITY category and authorised for this type.

8. Hand-over — state PID provider ​

When a state appoints a PID provider: the identity service's entry is handed over with successor_id, new issuance stops, and documents already issued stay valid until they expire (SPEC-TRUST-0001/TL8, RB-AP-ID-06). Verifier policies are updated to prefer the state PID; this type becomes DEPRECATED but stays verifiable.

9. Demo and pilot deviations ​

#DeviationClosure
S-15In the demo the identity provider may run in simulated (FAKE) modeReal provider in the pilot
S-9Keys in software in the demo walletSecure element in the pilot

FW-ARF-0001 · FW-TF-0001 · FW-RB-0001 · SPEC-ID-0003 · SPEC-PROTO-0001 · SPEC-PROTO-0002 · SPEC-CRED-0003 · SPEC-TRUST-0001 · ADR-0011 · ADR-0013

Change history ​

  • 0.1.1 (2026-09-27) — Display name "Tamga Identity Attestation"; Tamga's role is still that of a provisional provider (§0).
  • 0.1.0 (2026-09-27) — First draft: a compilation of ADR-0011, ADR-0013, SPEC-ID-0003 §8–9 and the RB-AP-ID rules. Awaiting approval.

Tamga ARF 0.3 · CC BY 4.0 · The Turkish text is the source; this is its official translation