Français

Verify a fata certificate

This page explains how to check a fata certificate, and what such a certificate proves.

How verification works

How to verify

  1. Scan the QR code printed on the certificate, or type its verification code in the box on this page.
  2. Check that the address bar shows fata.app: a forged certificate can carry a QR code leading to a look-alike page on another domain.
  3. Compare the page with the document in front of you: the name, the date and the security marks must match.

What is printed on the certificate

The code, the fingerprint, the pattern and the full signature appear identically on the verification page. A difference between the paper and the page means the document is not the one fata signed.

  • The QR code, top left, which leads to the certificate's verification page.
  • The line “Verify at fata.app/verify”, top right, under the date.
  • The verification code, just below it, in the form FATA-7K3M-9QX2-D4HB.
  • The signature fingerprint, in the form 4F2A 91C0 7BE3 55D8, printed up the left margin.
  • The security pattern, a small grid computed from the signature, in the bottom left corner.
  • The full digital signature, along the bottom edge.
  • The background and the border, drawn from the signature too, so they differ from one certificate to the next.

What the signature guarantees

fata signs every certificate as it is issued. The signature covers everything printed: the name, the title, the date, the issuing organization and the signatories. The verification page flags any later change to any one of them.

Technical details
  • The certificate is an Open Badges 3.0 credential, signed by fata with Ed25519 and the eddsa-jcs-2022 cryptosuite.
  • fata publishes its public keys at fata.app/.well-known/did.json. Each issuing organization's document, at fata.app/orgs/<orgId>/did.json, lists those same keys with fata as their controller.
  • Checking it does not have to go through fata: credential.json is attached to the PDF, the verification page offers it as a download, and any Open Badges 3.0 verifier checks it against those keys.

What the page can answer

  • Valid: the certificate is genuine and its content matches the signature.
  • Genuine, expired: the certificate was issued, but its validity ended on the date shown.
  • Revoked: the issuing organization withdrew it. The page gives the date and the reason.
  • Replaced by a corrected certificate: it was reissued, after a misspelled name for instance. The page links to the new one.
  • Invalid signature: the content does not match the signature. Do not rely on that certificate.
  • Not found: no certificate carries that code.

Who issues certificates

A certificate is issued by an organization: fata, or a partner organization using the fata platform. The verification page names it, and fata hosts and signs the certificate on its behalf. Every printed signatory is on their organization's register, confirmed by the person themselves or by fata; no other name can be printed as a signatory.

What a certificate does not prove

  • A challenge place is the organizer's claim. fata signs the certificate, but does not check the result it announces.
  • A skill assessment is timed and graded on fata's servers, but it is not proctored: nothing guarantees the person sat it alone.
  • The printed name is the one on the person's fata account. It is not checked against an identity document.

Privacy

fata publishes no list of certificates. A certificate can be read only with its code or its QR code, and appears on a public profile only if the person chooses to show it there.

Enter a verification code