Credential glossary

Credential verification

Credential verification is the process of establishing that a credential was genuinely issued by the organisation named on it, to the person named on it, and has not been altered since.

Last updated

Three questions, and only one of them is verification

Verification asks whether a credential is real: whether the organisation named on it actually issued it, to the person named on it, describing the award it describes. It is a question about a record, not about a document.

It is routinely confused with three neighbouring questions, and the confusions are worth separating because they have different answers and different costs.

  • Authentication asks whether the person in front of you is who they say they are. A perfectly verified credential belonging to somebody else tells you nothing, which is why a name on a certificate is checked against identity documents rather than against the certificate.
  • Accreditation asks whether the issuing organisation is reputable and whether its award means anything. A genuine certificate from a body nobody recognises is genuine and worthless, and verification will confirm it happily.
  • Inspection asks whether the document looks right. This is the one most often mistaken for verification, and it is the reason forgery works: every visual feature of a certificate can be reproduced by whoever is reproducing the certificate. Examining a certificate narrows the question. It never settles it.

Verifying a document versus verifying a record

Everything difficult about verification follows from one fact: a certificate is a copy, and a copy carries no information about whether the thing it copies exists.

Historically the only route from the copy back to the record ran through the issuer: find them, reach the right office, and hope they still hold files from the relevant year. Each of those steps can fail independently, and together they make verification expensive enough that most of the time it simply does not happen.

A verifiable credential removes that dependency by carrying its own proof. The check moves off the issuer's capacity to answer email and onto mathematics anyone can run, and what was a week becomes a few seconds.

What a successful verification does not tell you

A credential that verifies confirms four things: that this issuer issued this award, to this person, on this date, and that the record has not been altered since. That is genuinely useful and it is also the whole of it.

It does not tell you the award was difficult, that the standard was meaningful, that the holder still meets it, or that the person handing it to you is the person named. Verification establishes provenance. Judgement about what the credential is worth remains yours, and no amount of cryptography will do it for you.

Where to go from here

For the practical procedure, including what to do when a certificate carries no link at all, how to verify a certificate online is the step-by-step guide. If you are checking candidates as part of hiring, how employers verify certificates compares the five available routes. And if you issue credentials and want the question answered without your team answering it, credential verification as a feature covers what that involves.

Related terms

  • Verifiable credential

    A verifiable credential is a digital credential that carries its own cryptographic proof, so its authenticity can be confirmed from the credential itself rather than by contacting whoever issued it.

  • Credential ID

    A credential ID is the unique reference that identifies one issued credential, distinguishing it from every other credential the issuer has ever awarded.

  • Tamper-evident

    Tamper-evident means that any alteration to a record can be detected, which is a different and more achievable property than preventing the alteration in the first place.

Credentials that can be checked, not just looked at

We issue certificates and badges on behalf of organisations, each one signed and each one verifiable by anyone who receives it.