D
Independent verification
DSR Protocol · trust-minimised

Sızma Zeytinyağı — Extra Virgin Olive Oil

Brand: Ege KırsalıGTIN: 08690000000012Slug: tr-sunrise-zeytinyagi

How this works

  1. A fingerprint of the data. We take the public passport credential and compute a SHA-256 of it in canonical form.
  2. A signature you can check. That fingerprint sits inside a W3C Verifiable Credential signed with the issuer’s Ed25519 key. The key is part of the credential (a did:key), so verification needs nothing from us.
  3. A match. The fingerprint your browser computes right now must equal the one inside the signed credential. If a single byte changed, it fails.
  4. A history nobody can quietly rewrite. Every version is chained (SHA-256) to the one before it and published at /versions, so anyone can walk the whole trail v1→now and confirm nothing was swapped. A qualified eIDAS timestamp is on our roadmap.
Verification is read-only and anonymous. The signature key is derived from the credential itself — no database or network call to DSR is required to check it.