Verification
A claim is worth what its author is worth
Anyone can store a recycled-content figure. The question an auditor asks is who asserted it and when. CirculeID issues claims as signed credentials, so the answer is in the data rather than in someone's memory.
- Credentials
- W3C VC 2.0
- Issuer identity
- W3C DID
- Revocation
- Status list
Definition
How is a claim in a Digital Product Passport verified?
Claims such as recycled content are issued as W3C Verifiable Credentials, cryptographically signed by the party making the assertion under a Decentralized Identifier. A regulator or customer verifies the signature independently, without trusting CirculeID as an intermediary. That is the difference between a stored claim and a verifiable one.
Both specifications are W3C Recommendations: Verifiable Credentials 2.0 for the claim, Decentralized Identifiers for the issuer. Neither requires a blockchain, and neither depends on us.
The distinction
What a signature does and does not prove
| Question | Answer | How |
|---|---|---|
| Who asserted this? | Established | The issuer’s decentralized identifier, bound by the signature |
| When did they assert it? | Established | The issuance date inside the signed credential |
| Has it been altered since? | Established | Signature verification fails if any byte changed |
| Is it still current? | Established | Revocation and expiry checked at verification time |
| Is the value accurate? | Not established | That remains a question of the issuer’s competence and honesty |
Capabilities
The credential layer
Credential issuance
Conformity, recycled content, chain of custody and authenticity, each issued by the party that can assert it.
Issuer identity
Every issuing party holds a decentralized identifier that resolves independently of this platform.
Independent verification
Anyone holding the credential can verify it offline. Verification never requires calling CirculeID.
Revocation
A withdrawn certification stops verifying, checked against a status list at verification time.
Validity periods
Credentials expire, so a five-year-old footprint figure is not treated as a current one.
Key custody
Signing keys are held in a hardware security module, or by you, depending on how much you want us to hold.
How it works
From assertion to verification
- 01
Establish the issuer
The asserting organisation receives a decentralized identifier and a signing key it controls.
- 02
Issue the claim
The claim — recycled content, a certification, authenticity — is signed as a Verifiable Credential with its validity period.
- 03
Attach it to the passport
The credential travels with the product record, so the passport carries the evidence rather than pointing at it.
- 04
Verify anywhere
A regulator, customer or partner checks the signature and revocation status without contacting the issuer or us.
Answers
Frequently asked questions
What is the difference between a stored claim and a verifiable one?
A stored claim is a value in a database, true only insofar as you trust whoever runs the database. A verifiable claim is cryptographically signed by the party asserting it, so anyone can check who said it and that it has not been altered — without trusting the platform holding it, and without contacting the issuer.
Does a signature prove the claim is true?
No, and this distinction matters. A signature proves authorship and integrity: a named party asserted this specific value on this date, and nobody has changed it since. Whether the value is accurate remains a question of that party’s competence and honesty. What changes is that the assertion is now attributable.
Why use decentralized identifiers rather than certificates?
Because a passport has to remain verifiable for the life of the product, which can exceed the life of a certificate authority relationship or a vendor contract. A W3C Decentralized Identifier resolves independently, so a signature made in 2026 can still be checked in 2041 without depending on CirculeID still existing.
What happens if a certification is withdrawn?
The credential is revoked, and verification then fails rather than silently succeeding. Revocation is checked at verification time against a status list, which is why an expired or withdrawn certification does not keep validating simply because it was once genuine. Previously issued credentials remain valid for the period they covered.
Can this stop counterfeit products?
It makes authenticity checkable, which is a narrower claim than stopping counterfeiting. A counterfeit can copy a printed code; it cannot produce a credential signed by the brand’s key. So a determined counterfeiter can still copy an object, but they cannot make it verify — and verification takes a scan rather than an expert.
Next step
Make one claim verifiable
Pick the sustainability claim you would least like to defend without evidence. We will show you what it looks like signed.