Skip to content

Identity Rulebook ​

Document FW-RB-0003 · Version 1.0.0 · Status Active · Updated 2026-10-02 · Licence CC BY 4.0 Official English translation of the Turkish source text; in case of conflict the Turkish text prevails.

The rulebook for the identity credential Tamga issues as the provisional identity credential provider (urn:tamga:id:IdentityAttestation:1), branching from the Tamga RulebookA set of binding rules. The Tamga Rulebook holds the rules for all participants; each credential type has its own rulebook that branches from it. (FW-RB-0001): who issues it, with which identity proofingChecking that a person really is who they claim to be before a credential is issued, for example with an ID card and a liveness check., which attributes and which selective disclosure rule; validity and revocationWithdrawing a credential before it expires; the issuer marks it in a status list that verifiers check.; the two formats (SD-JWT VC (Selective Disclosure JWT Verifiable Credential)The JSON-based credential format with selective disclosure, used for online presentation in the EUDI Wallet and in Tamga. + ISO 18013-5 mdocThe ISO/IEC 18013-5 mobile document format, encoded in CBOR; used for in-person presentation and for the mobile driving licence.); rules for institutions and verifiers; hand-over to a state PID (Person Identification Data)The core identity data a state issues at the highest assurance level. Tamga does not take this role; its identity credential is not a PID. provider. Written on the pattern of the EUDI ARF (Architecture and Reference Framework)The document set that describes roles, architecture, trust model and rules. Tamga ARF follows the structure of the EU ARF. PID Rulebook — this document is not a PID but an EAA (Electronic Attestation of Attributes)The eIDAS term for a credential that attests attributes of a person, such as a degree or a membership..

0. Scope and status ​

TypevctCatalogue
Tamga identity credentialurn:tamga:id:IdentityAttestation:1schemas.tamga.network/v1/id/IdentityAttestation/1.0.0
The same credential as mdocdocType tamga.id.1ADR-0013

The technical definition is in SPEC-ID-0003 §9 and the schema catalogue; in a conflict they prevail. This rulebook creates no new rules; it gathers ADR-0011, ADR-0013, SPEC-ID-0003 and the RB-AP-ID rules of Annex B in one place, from the point of view of institutions and verifiers.

Status: this document is not a PID. While no state-appointed PID provider exists, it is an EAA that Tamga issues provisionally, as a non-qualified EAA; pid_providers[] stays empty in the trusted list. When a state provider is appointed, issuance stops and the entry is handed over to the successor (§8).

1. Data model ​

AttributeTypeSelective disclosureNote
given_name, family_namestringalways
birth_datedatealways
nationalityISO 3166-1 alpha-2always
personal_administrative_numberstringalwaysNational identity number; only in this type
document_typeID_CARD | PASSPORT | RESIDENCE_PERMIT | DRIVING_LICENSEalwaysThe document that was verified
document_number_hashsha256-…alwaysKeyed digest of the document number (HMAC-SHA256; key held only by the identity service) — not the number, and not recoverable from the digest
issuing_countryISO 3166-1 alpha-2always
document_chip_verifiedbooleanalwaysWhether the NFC chip was read (a fact, not a level)
verification_methodremote-document-liveness-face | remote-nfc-liveness-face | in-person | review-demoalwaysreview-demo only in the test credential issued for app store review
age_over_18booleanalwaysDerived; for age checks only this attribute is disclosed
status, category, cnf, vct, iss, iat, exp—neverTransport profile

Not included: portrait/photo, address, document images, an assurance level (LoA (Level of Assurance)How much confidence can be placed in an identity or a credential; Tamga uses separate levels for proofing (T), issuer (I) and wallet (W).) attribute. All personal attributes are selectively disclosable; a verifierThe party that checks a presented credential: signature, issuer in the trust list, status and policy. Also called relying party. may request only the attributes in its registered scope.

2. Who issues it ​

RequirementValue
IssuerThe Tamga Network identity service (id.tamga.network) — the only issuer; institutions cannot issue this type
Category / classIDENTITY · EAA · I2
Credential type authorityOnly in the identity service's entry (allow-list)
KeyThe identity service's credential signing key; a separate revocation list key (RB-AP-03)
RoleProvisional identity credential provider — not a PID Provider
App store reviewA separate test signer tamga-id-review (I1; verification_method: review-demo, at most 7 days); issued only with a single-use review code; passes no policy requiring I2

3. Identity proofing before issuance ​

PathLevelNote
Remote: document + liveness + face matchT2 (ETSI TS 119 461 Substantial)verification_method: remote-document-liveness-face
Remote + NFC chipT2; document_chip_verified: trueTechnically high; legally T3 is a qualified electronic signature
In personT2in-person

Rules: identity verification happens only in the identity service; institutional issuers, the wallet and verifiers do not talk to the provider. Before verification starts, an information notice is shown and explicit consent is obtained. The provider's decision is always confirmed from its decision endpoint; the webhook is only a trigger. A provider outage does not lower the level; issuance stops.

4. Data protection ​

  • Tamga is the data controller for this data.
  • Personal attributes are not kept after issuance; the permanent record is only an opaque subject_ref, the document number digest, the validity period and the revocation list positions. Document images, selfies, video and raw OCR data are never stored at Tamga.
  • An erasure request revokes the credential.
  • No second active identity credential is issued for the same document number; re-verification revokes the older one.

5. Validity and revocation ​

TopicRule
Validityexp = issuance + 730 days (≤ 2 years); re-verification after expiry
Revocation listMandatory (Token Status List)
Reasons for revocationthe person's deletion request, re-verification with the same document, reported loss/theft of the document, an incorrect credential
Copies10 copies, each on a different device key; a different copy per verifier

6. Two formats: SD-JWT VC and mdoc ​

The same credential is issued as SD-JWT VC (primary) and as ISO/IEC 18013-5 mdoc:

  • Attributes, iat/exp and the holderThe person who keeps a credential in their wallet and decides whom to show it to. key are identical in both formats.
  • The mdoc signature is ES256 and maps to the same trust anchorThe root key or certificate a verifier trusts first; everything else is checked back to it.; the result is three-valued.
  • The verifier chooses the format with DCQL (Digital Credentials Query Language)The query language a verifier uses in OpenID4VP to say which credentials and which fields it needs.; e.g. an age check in a browser asks for age_over_18 only, through mdoc.

7. Presentation and verification rules ​

UseAttributes requestedRule
Age checkage_over_18No other attribute is requested
Matching records at an institution (before issuing a credential)personal_administrative_number, birth_date, given_name, family_nameThe institution's issuing service receives them only within its registered scope and through the full verification pipeline; it does not store or log matching keys (RB-RP-ID-01)
"Holds a valid Tamga identity"noneReference policy event-tamga-id
Website sign-up / sign-in ("Sign in with Tamga")given_name, family_name at sign-up; none at sign-inThe account key is the per-site pseudonym; document_number_hash and the national ID number are not requested (RB-RP-13)
High-risk transactionper scopeFace matching, if needed, is the verifier's responsibility; the credential carries no portrait
  • A verifier requesting the identity number must have that attribute explicitly in its registration; the wallet flags out-of-scope requests.
  • The result is three-valued; INDETERMINATE is not acceptance.
  • The verifier must see the issuerThe institution that signs and issues credentials: a university, a professional body, a public institution or a company. in the trusted list in the IDENTITY category and authorised for this type.
  • PseudonymA stable account identifier the wallet derives separately for each website; two sites cannot link the same person. seed: together with the identity credential a separate type that cannot be presented, urn:tamga:id:PseudonymSeed:1 is issued; the seed is derived with a separate key from the person's stable identifier (in Türkiye the national ID number; otherwise country + document type + document number — pseudonyms then change when the document is renewed) and is not stored. The wallet derives a per-site pseudonym from it (RB-AP-ID-07).

8. Hand-over — state PID provider ​

When a state appoints a PID provider: the identity service's entry is handed over with successor_id, new issuance stops, and credentials already issued stay valid until they expire. Verifier policies are updated to prefer the state PID; this type becomes DEPRECATED but stays verifiable.

9. EU personal identification data (PID) and driving licence (mDL) ​

Tamga verifiers recognise the EU PID and the ISO driving licence (mDL (mobile Driving Licence)A driving licence held in a wallet in the mdoc format (ISO/IEC 18013-5).) as external types:

TypeFormat
urn:eudi:pid:1SD-JWT VC
eu.europa.ec.eudi.pid.1mdoc
org.iso.18013.5.1.mDLmdoc
  • Recognition condition. An external type is accepted only if its issuer is in the scope of an external list (Annex A §6.1) that vouches for that type. Today the list of lists contains no external list; each one is added by a separate decision.
  • Nested selective disclosureShowing only the fields a verifier asks for from a credential, and nothing else.. In the EU PID the address is an object and nationalities are an array. The person can reveal only what is needed: for example only the city of the address, or one of the nationalities. The verifier's scope check applies to the attribute itself or to its parent.
  • Age. The EU PID has no age attributes; in the EU a separate age verification credentialA digital document signed by an issuer and held in the person's wallet; the person shows only the fields that are asked for. is used for age. The mDL carries age elements such as age_over_18.

The attribute names of the Tamga identity credential are unchanged. EU PID equivalents:

Tamga identity credentialEU PID (SD-JWT VC)EU PID (mdoc)
given_namegiven_namegiven_name
family_namefamily_namefamily_name
birth_datebirthdatebirth_date
nationality (single value)nationalities (array)nationality (array)
personal_administrative_numberpersonal_administrative_numberpersonal_administrative_number
issuing_countryissuing_countryissuing_country
age_over_18— (separate age verification credential)—
document_type, document_number_hash, document_chip_verified, verification_methodno equivalent (Tamga-specific)no equivalent

When a state PID is available (§8), institutions may also accept the PID instead of the Tamga identity credential to match a person; this is enabled by a separate decision.

References ​

The decisions, specifications and standards this document rests on are listed in Annex E.

Status ​

Active — version 1.0.0 (2 October 2026).

Tamga ARF 1.0 · CC BY 4.0 · The Turkish text is the source; this is its official translation