Credential verification
Returns the public credential view, verification checks, status, replacement credential if superseded, and trust evidence.
/api/public/credentials/verify/[code]240 requests/minute
Public verification API
Public API routes expose credential status, JSON-LD proof, PDFs, verification receipts, issuer profiles, and Passport lookups. They are read-only, rate limited, and explicit when the registry cannot complete a check.
Registry contract
Illustrative contract view
GET /api/public/credentials/verify/NV-EXAMPLE-0001200 // verification.overall_statusapproved profile + verified domainsignature + payload hash + lifecycle503 is never treated as verifiedUse your configured Nyvarra host in non-production environments. Public responses intentionally exclude private holder emails, internal user IDs, and private Passport settings.
Endpoint ledger
The production base URL is https://nyvarra.app. Every route below is intentionally scoped to a public verification, export, receipt, issuer, or Passport workflow.
Returns the public credential view, verification checks, status, replacement credential if superseded, and trust evidence.
/api/public/credentials/verify/[code]240 requests/minute
Streams the archived or regenerated credential PDF for the public serial.
/api/public/credentials/[code]/pdf120 requests/minute
Returns the signed credential payload as application/ld+json.
/api/public/credentials/[code]/credential240 requests/minute
Exports the exact signed JSON-LD document, or compact VC-JWT when Accept: application/jwt is sent.
/api/public/credentials/[code]/open-badge240 requests/minute
Checks required contexts and fields, date validity, and supported Ed25519 proof integrity.
/api/open-badges/validate60 requests/minute
Generates a live PDF receipt containing status, checks, hashes, issuer context, and checked-at timestamp.
/api/public/credentials/[code]/verification-receipt120 requests/minute
Returns a sanitized public issuer profile, catalog, counts, and domain trust signals.
/api/public/issuers/[slug]180 requests/minute
Returns a privacy-filtered public Passport view. Add ?verification=1 for verifier-focused views.
/api/public/passports/[handle]180 requests/minute
Status semantics
The public page and API use the same core verification service. Client systems should branch on verification.overall_status and should not infer trust from visual certificate layout.
verifiedCryptographic proof passes and the credential lifecycle is active.
revokedThe issuer withdrew the credential. The original record remains visible.
supersededA corrected credential replaced this serial.
expiredThe credential passed its expiration date.
tamperedSignature, proof payload, or stored hash validation failed.
not_foundNo credential exists for the requested serial or code.
A 503 means the registry check did not complete. Do not cache it as a verified result, and do not substitute a visual certificate check.
Response contract
The response includes a sanitized certificate view, verification checks, and a replacement credential when a serial has been superseded. Use the receipt URL when a recruiter or compliance team needs a portable verification artifact.
Verification completed.
Credential, issuer, or Passport was not found.
Rate limit exceeded. Respect retry-after.
Registry temporarily unavailable. Do not treat as verified.
{
"success": true,
"certificate": {
"serial": "NV-EXAMPLE-0001",
"status": "issued",
"verification_url": "https://nyvarra.app/verify/NV-EXAMPLE-0001",
"verification_receipt_url": "https://nyvarra.app/api/public/credentials/NV-EXAMPLE-0001/verification-receipt",
"issuer": {
"name": "Example University",
"slug": "example-university",
"verified_domain": "example.edu"
}
},
"verification": {
"overall_status": "verified",
"cryptographic_valid": true,
"signature_valid": true,
"payload_matches_proof": true,
"payload_hash_matches": true,
"verified_at": "2026-07-10T12:00:00.000Z"
},
"replacement_certificate": null
}Illustrative credential verification response. Replacement credential data is returned when a serial has been superseded.
Operating boundaries
The public surface is intentionally easy to call and intentionally narrow in what it returns.