Institution-owned digital credentials
A university owns a digital credential program when it controls the issuer identity, signing authority, verification service, credential status, and export path. Software can support that work, but the institution must define the policy.
Five controls that make credentials durable
Ask for named owners, documented recovery paths, and testable evidence for each control. A valid badge does not prove that the institution can correct, verify, or preserve its records over time.
- Issuer identity
- Keep the public issuer identifier and its recovery process under institutional control.
- Signing authority
- Define who can use, rotate, suspend, and recover the keys that sign credentials.
- Verification
- Provide a public, documented route that checks the proof and current credential status.
- Credential records
- Preserve evidence, approval history, lifecycle changes, and corrections as institutional records.
- Exit control
- Export credentials, templates, evidence references, status history, and verification documentation before a platform change.
Evaluate the full credential lifecycle
During procurement, follow one representative credential from approval through issuance, verification, correction, and a possible platform transition.
Review the Open Badges 3 governance guide-
Step 1
Issue a representative credential
Use a real policy, named issuer, evidence record, and approval path. Confirm what becomes public before the learner receives it.
-
Step 2
Verify outside the issuing system
Check the public page, machine-readable export, proof, and current status in a separate browser session or with an independent verifier.
-
Step 3
Test a change and an exit
Suspend or revoke a sample credential, restore it when policy permits, then export the program record and document how verification will continue after a platform change.
Evidence that can be inspected
Review standards requirements, product capabilities, implementation evidence, and certification claims separately. Each supports a different procurement decision.
- Open Badges 3.0 requirements
The specification and conformance guide define credential roles, verification, status, and certification expectations.
- Verifiable Credentials model
The W3C model defines the credential, issuer, subject, proof, and credential-status concepts used across credential ecosystems.
- CredTrail public source code
Longsight publishes CredTrail’s source code so institutions can inspect or run its verification and credential-lifecycle implementation.
Where CredTrail fits
CredTrail is Longsight’s open-source credential product. Its product pages and documentation describe its support for governed issuance, public verification, wallet delivery, and institution-controlled deployment.
Longsight’s institutional guidance explains what a university should own and test, whether or not it selects CredTrail.