Skip to content

The VitalCV Wallet is free for clinicians. Check your NPI

This page explains VitalCV’s evidence and signing architecture. It is not a clinician record and does not represent a completed credentialing decision.

The state rows below are an architectural illustration of the trust-state grammar (example run ids and timestamps), not live source-check results. For a human-readable overview, see the Trust Center. The machine-readable register is served at /.well-known/trust-register.

Trust State Register

Institutional trust surface for VitalCV credential verification

Doctrine v1.0 · pilot · did:web:vitalcv.com
Proof Tier Vocabulary
T1 · Self-Asserted

Clinician-provided, not verified

T2 · Inferred

Derived from verified data

T3 · Source Checked

Checked against authoritative source

T4 · Issuer Signed

Cryptographically signed by issuer

State Vocabulary
ANONYMOUS PREVIEWExploratory, unowned — no lineage attribution
OWNED SNAPSHOTAttributed, replay-visible — example lineage
SIGNED ARTIFACT (EXAMPLE)Cryptographic plane — issuer-signed, T4 capable
ANONYMOUS PREVIEW
Anonymous Preview

Exploratory view — no ownership attribution, no lineage, no replay. All slots are unbound.

OBJECT
NPPES Identity
OWNERSHIP
─ ─ ─
CHECKED_AT
─ ─ ─
CHANNEL
CMS NPPES Registry
REPLAY
─ ─ ─
RUN_ID
──────
T1 · Self-Asserted
OBJECT
OIG Exclusions
OWNERSHIP
─ ─ ─
CHECKED_AT
─ ─ ─
CHANNEL
OIG LEIE
REPLAY
─ ─ ─
RUN_ID
──────
T1 · Self-Asserted
OBJECT
State License
OWNERSHIP
─ ─ ─
CHECKED_AT
─ ─ ─
CHANNEL
State Board
REPLAY
─ ─ ─
RUN_ID
──────
T1 · Self-Asserted
OWNED SNAPSHOT
Owned Snapshot

Attributed to vcv-system. Lineage is visible; replay is tracked. Source checks applied.

OBJECT
NPPES Identity
OWNERSHIP
vcv-system
CHECKED_AT
2026-01-01 00:00:00 UTC
CHANNEL
CMS NPPES Registry
REPLAY
─ ─ ─
RUN_ID
3760c3bc
T3 · Source Checked
OBJECT
OIG Exclusions
OWNERSHIP
vcv-system
CHECKED_AT
─ ─ ─
CHANNEL
OIG LEIE
REPLAY
─ ─ ─
RUN_ID
3760c3bc
T1 · Self-Asserted
OBJECT
No adverse result returned
OWNERSHIP
vcv-system
CHECKED_AT
2026-01-01 00:00:00 UTC
CHANNEL
OIG LEIE
REPLAY
─ ─ ─
RUN_ID
3760c3bc
T3 · Source Checked
REPLAY CONTINUITYfirst run — no prior lineage
SIGNED INSTITUTIONAL ARTIFACT
Signed artifact (example)

Cryptographic plane. Issuer-signed (ES256), T4-capable — the signed-receipt grammar shown as an example, not a live artifact.

OBJECT
NPPES Identity
OWNERSHIP
vcv-es256-prod-1
CHECKED_AT
2026-01-01 00:00:00 UTC
CHANNEL
CMS NPPES Registry
REPLAY
Issuer continuity (example)
RUN_ID
3760c3bc
T4 · Issuer Signed
OBJECT
Receipt Issued
OWNERSHIP
did:web:vitalcv.com
CHECKED_AT
2026-01-01 00:00:00 UTC
CHANNEL
VitalCV Issuer
REPLAY
Replay-verifiable by design
RUN_ID
3760c3bc
T4 · Issuer Signed
OBJECT
No adverse result returned
OWNERSHIP
vcv-es256-prod-1
CHECKED_AT
2026-01-01 00:00:00 UTC
CHANNEL
OIG LEIE
REPLAY
─ ─ ─
RUN_ID
3760c3bc
T3 · Source Checked
REPLAY CONTINUITYfirst run — no prior lineage
Issuer Continuity
Issuer
did:web:vitalcv.com
Key Fingerprint
vcv-es256-prod-1verify →
EC P-256 · ES256 · Active
Last Rotation
N/A
Verify issuer →

/.well-known/did.json · did:web:vitalcv.com

machine-readable: /.well-known/trust-register

Trust Doctrine

Anonymous readsPUBLIC
Anonymous writesREJECTED — 401
Authenticated writesATTRIBUTABLE — actor_id required
Replay lineageCOHERENT — Prisma upsert, dedupeKey
Verifier continuityPUBLIC — no auth required
Signed issuanceATTRIBUTABLE — azp + vcv.actor_id in JWT
Degraded-state semanticsEXPLICIT — dashed borders, no opacity

Infrastructure Continuity

Replay survivabilityConfirmed — Prisma upsert deduplication
Receipt continuityActive

Verifier Guarantees

You can verify any VitalCV receipt without contacting VitalCV.
Public key published at /.well-known/jwks.json.
DID document at /.well-known/did.json.
No API key required for verification.

Live Operational Status

Independently verifiable. No auth required.

/status →

Machine-Readable Endpoints

EndpointDescriptionAuth
/.well-known/jwks.jsonPublic signing keysNone
/.well-known/did.jsonW3C DID documentNone
/.well-known/openid-credential-issuerOID4VCI metadataNone
/.well-known/trust.jsonTrust manifestNone
/.well-known/trust-registerMachine-readable doctrineNone
/trust/graphVerifier-readable trust graphNone
/trust/schemaTrust graph schema referenceNone
/trust/doctrineReplay contract doctrineNone
/api/receipts/verifyVerify a receipt JWTNone

Human-Readable Trust Surfaces