Guides

Issuing verifiable credentials

Design credential templates, issue them to your people, and let anyone verify them at a public link — signed and endorsed by Miatz.

  • Every credential is cryptographically signed and independently verifiable — no login, no phone call
  • The Itz'at · Verified by Miatz mark travels with the credential wherever it is shared
  • Revocation and expiry are built in, so a credential always reflects the truth today
  • A person keeps their credentials on their own permanent account, even after they leave

What an Itz'at credential is

An Itz'at credential is a verifiable record that a person earned a defined achievement in your organization. It follows the Open Badges 3.0 / W3C Verifiable Credentials standard, so it is:

  • Signed — with an Ed25519 key, so any change to its contents breaks the signature.
  • Endorsed by Miatz — a separate co-signature that anchors the non-removable Itz'at · Verified by Miatz mark.
  • Independently verifiable — anyone can check it at a public link or by uploading the credential file, with no login and no request to you.

Designing a credential

A template defines the achievement: its name, what it represents, how it is earned, the skills it evidences, and whether it expires. Templates start as drafts you can edit freely. When you publish one it becomes issuable and is locked — this is deliberate, so that the meaning of every credential already issued from it can never shift.

Keep the language honest: describe the achievement and how it was earned. Avoid words like "degree", "diploma" or "accredited" — an Itz'at credential is a verifiable achievement, not an academic qualification.

Issuing

On the Credentials screen, choose a published credential and a member. That is all you supply — Miatz's isolated signer does the rest: it assembles the credential, signs it, co-signs the Miatz endorsement, allocates its slot in the revocation list, and publishes it. The signing key never enters the app, and no one can hand in a pre-made credential.

Verifying

Every credential has a public verify page and a QR code. Opening it re-computes the signature and checks the live revocation status, then reports valid, expired or revoked — always with the non-removable mark. A verifier can also upload the credential file to check it offline against the published revocation list.

Revoking and renewing

Revoke a credential and it fails every future verification at once — recorded both as its state and as a bit in the public revocation list, so offline verifiers see it too. Revocation is permanent, and the history is preserved.

Credentials with an expiry appear in the renewal pipeline as their date approaches. Renewing issues a fresh credential from the same template.

Who can do what

Designing, issuing and revoking credentials is limited to owners, org admins and enablement managers, and the database enforces that — not just the screen. A person keeps every credential on their own permanent Miatz account, so it stays theirs even after they leave your organization.

Frequently asked

What is an Itz'at credential?

An Open Badges 3.0 Verifiable Credential — a tamper-evident, cryptographically signed record that a person earned a specific achievement in your organization. Anyone can verify it at its public link without contacting you, and Miatz co-signs each one as an independent endorsement.

How do I create one?

Open Credentials and choose New credential. Give it a name, describe how it is earned, add any skills, and set whether it expires. Save it as a draft while you refine it, then Publish it to make it issuable. Published templates are locked so that what an issued credential attests can never change underneath it.

How is a credential issued?

Pick a published credential and a member on the Credentials screen. Miatz's isolated signer assembles the credential, signs it with an Ed25519 key that never touches the app, co-signs the Miatz endorsement, and publishes it. You only ever choose who receives what — the signing happens in one isolated place.

How does someone verify a credential?

Every credential has a public verify page and a QR code. The page re-computes the signature and checks the live revocation status, then shows whether it is valid, expired or revoked — always with the non-removable Itz'at · Verified by Miatz mark. Verifiers can also upload the credential file to check it offline.

What happens when I revoke a credential?

It fails every future verification immediately. Revocation is permanent and is recorded both as the credential's state and as a bit in a public revocation list, so even offline verifiers see the change. Existing history is never erased — the record that it was issued and then revoked is kept.

What about expiry and renewal?

If a template sets a validity period, issued credentials carry an expiry date and appear in the renewal pipeline as that date approaches. Renewing issues a fresh credential from the same template; the expired one is not reactivated.

Is this a degree or an accreditation?

No. An Itz'at credential is a verifiable record of an achievement your organization defines and Miatz endorses. It is not a degree, diploma, academic qualification or accreditation, and it is not a guarantee of employment.

Related guides

Was this helpful?

Try it, don't just read about it

Founding cohorts are free. Take the DSAT and see this from the inside.