What are verifiable credentials? A guide for education and HR.

A verifiable credential is a certificate in digital form that is cryptographically signed by the organisation that issues it. The holder keeps it in a digital wallet and presents it when needed. Anyone who receives it can check, in seconds and without contacting the issuer, that it is authentic, unchanged and still valid.

Updated · SAPIO GmbH

How a verifiable credential works

The issuer describes an achievement as structured data (who, what, when, by whom) and signs it with a key that belongs to the institution. The signed credential is delivered to the holder, who stores it in a wallet app on their phone.

When the holder applies for a job or a place on a programme, they present the credential, usually by scanning a QR code. The verifier’s software checks the signature against the issuer’s published identity and looks up the revocation status. The result is available immediately.

Why it matters for institutions

Registrars spend time confirming certificates for employers and other universities. With verifiable credentials that confirmation happens automatically, while the institution stays the authoritative source of what it issued.

Forged PDFs and edited transcripts stop being a problem: a changed credential no longer matches its signature.

The standards behind it

Interoperability comes from open standards rather than from one vendor. The ones that matter in Europe and Switzerland today are:

  • SD-JWT VC: the credential format, with salted hashes for selective disclosure.
  • OpenID4VCI and OpenID4VP: OpenID Foundation protocols to issue credentials into a wallet and to present them.
  • Issuer identity: a decentralised identifier such as did:webvh, anchored in the issuer’s own web domain, or trust lists run by an ecosystem.
  • European Learning Model (ELM): the EU vocabulary for describing learning achievements, used by Europass Digital Credentials.

Verifiable credentials are not blockchain

Verifiable credentials do not need a blockchain. Signatures and status lists are published over the web. SAPIO uses no blockchain, tokens or cryptocurrency.

What an institution needs to start

A credential definition (fields, validity, design), an issuer identity, a platform to issue and track credentials, and a short test with real learners. With SAPIO a first pilot typically takes four weeks from the first working session to production issuance.

Questions

Is a verifiable credential the same as a PDF certificate with a QR code?

No. A QR code on a PDF usually links to a portal run by the issuer, which must stay online. A verifiable credential carries its own cryptographic proof and is checked against the issuer’s published key.

Who owns a verifiable credential?

The holder keeps it in their own wallet and decides when to share it. The issuer remains responsible for its content and can revoke it.

Do verifiers need special software?

They need a verification service that supports OpenID4VP. With SAPIO a verifier uses a browser-based verification flow; no integration is required on their side.

Want to see it with your own credential?

In 30 minutes we walk through your credential type and show issuance and verification live.