Issue
An approved issuer creates a record under its authorized organization account.
Canonicalize
The system normalizes the record into the protocol’s stable data structure.
Protect
The canonical record is hashed with SHA-256. Ed25519 signing remains the next production gate.
Register
The canonical record, integrity references and audit event are stored.
Generate
A QR image is generated containing the public verification URL—not private data.
Verify
A scan resolves issuer authority, current state, expiration and stored hash integrity.
Revoke
An authorized issuer can withdraw a record and preserve the lifecycle audit trail.
Core implementation rule
