Overview
Developers
Nyvarra API
Check Nyvarra certificates from your own software: an applicant tracking system, an admissions portal, a hospital's credentialing desk. The verification API is public and needs no key. Issuers can also read their own certificates with an issuer API key.
Base URL https://nyvarra.app
- Verification APICheck any certificate by serial or by its PDF file, and fetch its signed record, PDF and receipt.Public · no key
- Issuer APIRead your organization's own certificates by serial, as they stand today, for your own website or records.Bearer key · on request
- Open Badges 3.0Export certificates as verifiable credentials, validate Open Badges from anywhere, and import them.JSON-LD · VC-JWT
Quickstart
Every Nyvarra certificate carries a serial, like NV-000142, printed on it and in its QR code. Send the serial to the verify endpoint. There's nothing to sign up for.
Decide on verification.overall_status. Only verified means the certificate is genuine and current. Every other value, and every failed request, means don't accept it yet. The statuses are listed in the reference.
Then compare the name and details in certificate with the document you were given. A genuine result proves the issuer issued this certificate to this person; it doesn't prove the person in front of you is them.
curl https://nyvarra.app/api/public/credentials/verify/NV-000142{
"success": true,
"certificate": {
"serial": "NV-000142",
"status": "issued",
"issued_at": "2026-09-14T09:30:00.000Z",
"recipient": { "full_name": "Ayesha Siddiqui", "registration_number": null },
"event": { "title": "Basic Life Support Workshop", "achievement": "Basic Life Support Workshop" },
"issuer": {
"name": "Example Medical College",
"slug": "example-medical-college",
"verified_domain": "example.edu.pk",
"assurance_label": "Organization domain verified"
}
},
"verification": {
"overall_status": "verified",
"cryptographic_valid": true,
"verified_at": "2026-10-07T08:12:44.120Z"
},
"replacement_certificate": null
}Requests and responses
- Everything is served over HTTPS from
https://nyvarra.app. - Responses are JSON unless the endpoint returns a file (PDF, JPEG, JSON-LD or JWT). JSON bodies always carry
success; when it'sfalsethere is anerrorsentence you can log or show. - Timestamps are ISO 8601 in UTC. Hashes are lowercase hexadecimal SHA-256.
- New fields are added over time. Ignore fields you don't recognise rather than rejecting the response.
- Call the API from your server. It doesn't send CORS headers, so a browser on another site can't call it directly.
- Answers describe the certificate right now. Withdrawals take effect at once, so don't cache a result for longer than your own decision needs it.
{
"success": false,
"error": "Credential registry is temporarily unavailable."
}Errors
Nyvarra uses ordinary HTTP status codes. The ones you'll meet:
| Code | Meaning | What to do |
|---|---|---|
400 | The request was malformed, such as a fingerprint that isn't 64 hexadecimal characters. | Fix the request. Retrying won't help. |
401 | Issuer API only: the key is missing, revoked or doesn't have access. | Check the Authorization header. |
404 | No certificate, issuer or Passport matches. | Treat as not found. Check the serial was typed correctly. |
409 | The certificate can't be exported in the format asked for. | Ask for the JSON-LD form instead. |
410 | The certificate was withdrawn or replaced, so its files are no longer served. | Call the verify endpoint for its current status. |
413 | The document sent is too large. | Stay under the size limit for that endpoint. |
422 | Open Badge validation ran and the credential isn't valid. | Read validation.errors. |
429 | Too many requests from your address. | Wait for retry-after seconds, then retry. |
503 | The check couldn't be completed just now. | Retry after retry-after seconds. Never treat it as genuine. |
Rate limits
Public endpoints are limited per network address, per minute. The issuer API is limited per key. When you go over, you get a 429 with retry-after in seconds and the limit headers shown here.
| Endpoint | Per minute |
|---|---|
| Verify by serial, signed credential | 240 |
| Issuer profile, Passport | 180 |
| Verify by PDF file, artifact manifest, issuer directory | 120 |
| Open Badge export | 60 |
| Certificate PDF, verification receipt | 30 |
| Open Badge validation | 20 |
| Issuer API lookup (per key, 100 serials a call) | 600 |
Endpoints that build files refuse requests rather than run unprotected if the limit can't be counted; they answer 503 with retry-after. Need more for a migration or an audit? Write to [email protected].
HTTP/1.1 429 Too Many Requests
retry-after: 41
x-ratelimit-limit: 240
x-ratelimit-remaining: 0
x-ratelimit-reset: 2026-10-07T08:13:00.000Z
x-ratelimit-source: database
cache-control: no-storeWhere it works
Nyvarra serves organizations in a limited set of countries, but certificates are checked from everywhere.
| Endpoints | Reachable from |
|---|---|
| Verify by serial or PDF file, certificate files, signed credential, Open Badge export, receipt | Anywhere, including cloud servers and VPNs |
| Issuer API | Anywhere, with a key |
| Issuer directory and profile, Passport, Open Badge validation | Countries Nyvarra serves, not from VPN, proxy or hosting-provider addresses |
A request to the last group from elsewhere is redirected (307) to /not-available. If your servers sit outside those countries and you need the issuer endpoints, tell us.
Current availability of every part of Nyvarra is on the status page, checked every 15 minutes.