CirculeID

Verification

A claim is worth what its author is worth

Anyone can store a recycled-content figure. The question an auditor asks is who asserted it and when. CirculeID issues claims as signed credentials, so the answer is in the data rather than in someone's memory.

Credentials
W3C VC 2.0
Issuer identity
W3C DID
Revocation
Status list

Definition

How is a claim in a Digital Product Passport verified?

Claims such as recycled content are issued as W3C Verifiable Credentials, cryptographically signed by the party making the assertion under a Decentralized Identifier. A regulator or customer verifies the signature independently, without trusting CirculeID as an intermediary. That is the difference between a stored claim and a verifiable one.

Both specifications are W3C Recommendations: Verifiable Credentials 2.0 for the claim, Decentralized Identifiers for the issuer. Neither requires a blockchain, and neither depends on us.

The distinction

What a signature does and does not prove

Being precise here is the difference between a technical argument that survives due diligence and one that does not.
What a verifiable credential establishes, and what it does not
QuestionAnswerHow
Who asserted this?EstablishedThe issuer’s decentralized identifier, bound by the signature
When did they assert it?EstablishedThe issuance date inside the signed credential
Has it been altered since?EstablishedSignature verification fails if any byte changed
Is it still current?EstablishedRevocation and expiry checked at verification time
Is the value accurate?Not establishedThat remains a question of the issuer’s competence and honesty

Capabilities

The credential layer

  • Credential issuance

    Conformity, recycled content, chain of custody and authenticity, each issued by the party that can assert it.

  • Issuer identity

    Every issuing party holds a decentralized identifier that resolves independently of this platform.

  • Independent verification

    Anyone holding the credential can verify it offline. Verification never requires calling CirculeID.

  • Revocation

    A withdrawn certification stops verifying, checked against a status list at verification time.

  • Validity periods

    Credentials expire, so a five-year-old footprint figure is not treated as a current one.

  • Key custody

    Signing keys are held in a hardware security module, or by you, depending on how much you want us to hold.

How it works

From assertion to verification

  1. 01

    Establish the issuer

    The asserting organisation receives a decentralized identifier and a signing key it controls.

  2. 02

    Issue the claim

    The claim — recycled content, a certification, authenticity — is signed as a Verifiable Credential with its validity period.

  3. 03

    Attach it to the passport

    The credential travels with the product record, so the passport carries the evidence rather than pointing at it.

  4. 04

    Verify anywhere

    A regulator, customer or partner checks the signature and revocation status without contacting the issuer or us.

Answers

Frequently asked questions

What is the difference between a stored claim and a verifiable one?

A stored claim is a value in a database, true only insofar as you trust whoever runs the database. A verifiable claim is cryptographically signed by the party asserting it, so anyone can check who said it and that it has not been altered — without trusting the platform holding it, and without contacting the issuer.

Does a signature prove the claim is true?

No, and this distinction matters. A signature proves authorship and integrity: a named party asserted this specific value on this date, and nobody has changed it since. Whether the value is accurate remains a question of that party’s competence and honesty. What changes is that the assertion is now attributable.

Why use decentralized identifiers rather than certificates?

Because a passport has to remain verifiable for the life of the product, which can exceed the life of a certificate authority relationship or a vendor contract. A W3C Decentralized Identifier resolves independently, so a signature made in 2026 can still be checked in 2041 without depending on CirculeID still existing.

What happens if a certification is withdrawn?

The credential is revoked, and verification then fails rather than silently succeeding. Revocation is checked at verification time against a status list, which is why an expired or withdrawn certification does not keep validating simply because it was once genuine. Previously issued credentials remain valid for the period they covered.

Can this stop counterfeit products?

It makes authenticity checkable, which is a narrower claim than stopping counterfeiting. A counterfeit can copy a printed code; it cannot produce a credential signed by the brand’s key. So a determined counterfeiter can still copy an object, but they cannot make it verify — and verification takes a scan rather than an expert.

Next step

Make one claim verifiable

Pick the sustainability claim you would least like to defend without evidence. We will show you what it looks like signed.

Index