What an anchor verifies

A wallet presents an attestation signed by its issuer. Todis verifies that signature, then follows the issuer's certificate chain up to a trust anchor: in mdoc format (ISO/IEC 18013-5), the issuing authority certificate authority, known as the IACA, or the signing certificate that an official list publishes; in SD-JWT VC format, the issuer's certificate authority. An attestation that chains to no anchor is refused, and the verification result states the reason.

Each anchor only counts for the attestation types shown on its card: an authority declared for identity does not validate a proof of age. Your application has no anchor to supply or keep up to date: Todis alone holds them, and refuses any in a request.

Where the anchors come from

Official lists first. When an official trusted list exists for an attestation type, Todis reads it and it prevails in its domain, like the European Commission's trusted list for age verification (ETSI TS 119 612). Its signature is checked against the certificates the Commission publishes, its next update date is checked, and an issuer it withdraws leaves the registry.

Todis declarations next, for issuers that no published list covers yet, such as France Identité. Each one carries its source, and an official list that later covers the same issuer takes over with no interruption.

The registry is republished whenever a source changes, and the service reloads it without restarting. On the integration platform, anchors marked "Test" serve interoperability testing: they are never accepted in production.

The registry

Source: GET /trust/registries, described in the technical reference.