Skip to main content
Overview

Developers

Nyvarra API

Check Nyvarra certificates from your own software: an applicant tracking system, an admissions portal, a hospital's credentialing desk. The verification API is public and needs no key. Issuers can also read their own certificates with an issuer API key.

Base URL https://nyvarra.app

Quickstart

Every Nyvarra certificate carries a serial, like NV-000142, printed on it and in its QR code. Send the serial to the verify endpoint. There's nothing to sign up for.

Decide on verification.overall_status. Only verified means the certificate is genuine and current. Every other value, and every failed request, means don't accept it yet. The statuses are listed in the reference.

Then compare the name and details in certificate with the document you were given. A genuine result proves the issuer issued this certificate to this person; it doesn't prove the person in front of you is them.

Request
curl https://nyvarra.app/api/public/credentials/verify/NV-000142
200 OK
{
  "success": true,
  "certificate": {
    "serial": "NV-000142",
    "status": "issued",
    "issued_at": "2026-09-14T09:30:00.000Z",
    "recipient": { "full_name": "Ayesha Siddiqui", "registration_number": null },
    "event": { "title": "Basic Life Support Workshop", "achievement": "Basic Life Support Workshop" },
    "issuer": {
      "name": "Example Medical College",
      "slug": "example-medical-college",
      "verified_domain": "example.edu.pk",
      "assurance_label": "Organization domain verified"
    }
  },
  "verification": {
    "overall_status": "verified",
    "cryptographic_valid": true,
    "verified_at": "2026-10-07T08:12:44.120Z"
  },
  "replacement_certificate": null
}
Shortened. The full object is in the Verification API reference.

Requests and responses

  • Everything is served over HTTPS from https://nyvarra.app.
  • Responses are JSON unless the endpoint returns a file (PDF, JPEG, JSON-LD or JWT). JSON bodies always carry success; when it's false there is an error sentence you can log or show.
  • Timestamps are ISO 8601 in UTC. Hashes are lowercase hexadecimal SHA-256.
  • New fields are added over time. Ignore fields you don't recognise rather than rejecting the response.
  • Call the API from your server. It doesn't send CORS headers, so a browser on another site can't call it directly.
  • Answers describe the certificate right now. Withdrawals take effect at once, so don't cache a result for longer than your own decision needs it.
Error body
{
  "success": false,
  "error": "Credential registry is temporarily unavailable."
}

Errors

Nyvarra uses ordinary HTTP status codes. The ones you'll meet:

CodeMeaningWhat to do
400The request was malformed, such as a fingerprint that isn't 64 hexadecimal characters.Fix the request. Retrying won't help.
401Issuer API only: the key is missing, revoked or doesn't have access.Check the Authorization header.
404No certificate, issuer or Passport matches.Treat as not found. Check the serial was typed correctly.
409The certificate can't be exported in the format asked for.Ask for the JSON-LD form instead.
410The certificate was withdrawn or replaced, so its files are no longer served.Call the verify endpoint for its current status.
413The document sent is too large.Stay under the size limit for that endpoint.
422Open Badge validation ran and the credential isn't valid.Read validation.errors.
429Too many requests from your address.Wait for retry-after seconds, then retry.
503The check couldn't be completed just now.Retry after retry-after seconds. Never treat it as genuine.

Rate limits

Public endpoints are limited per network address, per minute. The issuer API is limited per key. When you go over, you get a 429 with retry-after in seconds and the limit headers shown here.

EndpointPer minute
Verify by serial, signed credential240
Issuer profile, Passport180
Verify by PDF file, artifact manifest, issuer directory120
Open Badge export60
Certificate PDF, verification receipt30
Open Badge validation20
Issuer API lookup (per key, 100 serials a call)600

Endpoints that build files refuse requests rather than run unprotected if the limit can't be counted; they answer 503 with retry-after. Need more for a migration or an audit? Write to [email protected].

429 response headers
HTTP/1.1 429 Too Many Requests
retry-after: 41
x-ratelimit-limit: 240
x-ratelimit-remaining: 0
x-ratelimit-reset: 2026-10-07T08:13:00.000Z
x-ratelimit-source: database
cache-control: no-store

Where it works

Nyvarra serves organizations in a limited set of countries, but certificates are checked from everywhere.

EndpointsReachable from
Verify by serial or PDF file, certificate files, signed credential, Open Badge export, receiptAnywhere, including cloud servers and VPNs
Issuer APIAnywhere, with a key
Issuer directory and profile, Passport, Open Badge validationCountries Nyvarra serves, not from VPN, proxy or hosting-provider addresses

A request to the last group from elsewhere is redirected (307) to /not-available. If your servers sit outside those countries and you need the issuer endpoints, tell us.

Current availability of every part of Nyvarra is on the status page, checked every 15 minutes.