Building a Credential Verification System on the Blockchain

When developing a credential verification system for a DeFi protocol, we faced the need to verify users' KYC status without disclosing their personal data. Standard blockchain verification reveals all credential attributes, violating privacy. The solution is verifiable credentials using ZK-proof (Gr

Blockchain Development Services

Frequently Asked Questions

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1441
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1301
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    998
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1267
  • image_logo-advance_0.webp
    B2B Advance company logo design
    713
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    1003

When developing a credential verification system for a DeFi protocol, we faced the need to verify users' KYC status without disclosing their personal data. Standard blockchain verification reveals all credential attributes, violating privacy. The solution is verifiable credentials using ZK-proof (Groth16 or PLONK), which allow proving only the required fact. This infrastructure is standardized by W3C (W3C Verifiable Credentials Standard) and supported by wallets (MetaMask, WalletConnect) and protocols. We implement the full cycle: issuance, storage, verification, and revocation of digital credentials based on W3C Verifiable Credentials standards. The system can integrate with existing KYC providers (Persona, Jumio) and run on Ethereum, Polygon, or Arbitrum. Gas savings with ZK-proof on L2 amount to up to 70% — with 1000 verifications per day, this saves over $500 per month.

Architecture of Verification on the Blockchain

The system is built from three key components:

  • Issuer — a trusted organization (KYC provider, educational institution, DAO) that issues signed credentials via its own DID.
  • Holder — a user storing credentials (e.g., in a wallet or via Polygon ID).
  • Verifier — a protocol or dApp that checks credentials before granting access.

The verifier generates a unique challenge (nonce); the holder includes it in the Verifiable Presentation and signs it. This prevents replay attacks: the presentation is valid only for that specific request.

// User creates a presentation const presentation = { "@context": ["https://www.w3.org/2018/credentials/v1"], "type": ["VerifiablePresentation"], "verifiableCredential": [kycCredential], "proof": { "type": "Ed25519Signature2020", "challenge": nonce, "domain": "app.example.com", "created": new Date().toISOString(), "verificationMethod": `did:ethr:${userAddress}#controller`, "proofPurpose": "authentication", "jws": await signPresentation(nonce) } }; 

Necessity of ZK-Verification

Standard verification reveals the entire credential: the protocol sees the issuer, issuance date, and all attributes. ZK-proof (Groth16 or PLONK) changes this: the user proves a fact ("I have a valid KYC credential") without revealing its content. This approach is required for:

  • DeFi lending — verify that a borrower passed KYC without disclosing their identity.
  • DAO governance — grant voting rights only to holders of Contributor SBTs, without showing who holds them.
  • Compliant DEX — allow trading only for verified addresses from allowed jurisdictions.

ZK-proof accelerates verification by 3–5 times compared to full verification (when using Plookup-based frameworks) and provides the confidentiality required by GDPR.

How ZK-proof Protects Privacy?

A ZK-proof allows the verifier to be convinced of a statement's truth without seeing the original data. For example, a user proves they are over 18 without presenting their passport. This is achieved with circuits written in circom and snarkjs. An on-chain registry stores only a hash or state snapshot; full credentials remain with the user.

What is On-chain Registry?

An on-chain registry is a smart contract that stores references to current credentials or their fingerprints. When a credential is revoked, the issuer updates the registry, and the verifier checks the status. This approach ensures transparency and immutability but requires gas management. We optimize gas consumption by storing only data necessary for verification.

Our Approach: What's Included in Development

We design the system turnkey from scratch or integrate with an existing architecture. Our development includes:

  1. Select the standard (W3C VC + DID or Polygon ID for ZK).
  2. Deploy an on-chain Registry smart contract on Ethereum/Polygon/Arbitrum (your choice).
  3. Integrate trusted issuers (Persona, Jumio, Onfido, or your own).
  4. Develop a Verifier SDK (ethers.js, viem) for use in the protocol.
  5. Implement ZK circuits (circom + snarkjs) and a verifier smart contract (if needed).
  6. Conduct a security audit (Slither, Mythril, Echidna fuzzing).
  7. Deliver documentation, tests, and deployment instructions.

Comparison of Verification Methods

Method Privacy Gas cost (L2) Verification time Standard support
Standard VC verification Low (reveals all data) ~50,000 gas <1 sec W3C VC + DID
ZK-proof (Groth16) High (only fact) ~300,000 gas 2–3 sec Polygon ID, circom
ZK-proof (PLONK) High (only fact) ~200,000 gas 1–2 sec PLONK, Halo2
On-chain commitment + off-chain verification Medium (hash) ~30,000 gas <1 sec Custom

Development Stages

Stage Duration Result
Analytics 1–2 weeks Technical specification, stack selection
Design 1–2 weeks Smart contract and ZK circuit architecture
Implementation 4–8 weeks Contracts, circuits, SDK, tests
Audit 1–2 weeks Security report
Deployment 1 week Network deployment, integration
Support 3 months Documentation, training, refinements

Process

  1. Analytics — clarify credential types, number of issuers, privacy requirements.
  2. Design — choose stack (Foundry/Hardhat, circom/snarkjs), smart contract architecture.
  3. Implementation — write contracts, ZK circuits, SDK, tests (unit + integration).
  4. Audit — internal and external security audit.
  5. Deployment — deploy on the chosen network, integrate with your protocol.
  6. Support — documentation, team training, 3-month warranty support.
Example circom configuration for KYC
pragma circom 2.0.0; include "../../node_modules/circomlib/circuits/comparators.circom"; template KYCCredential(ageThreshold) { signal input age; signal input country; signal input isKYC; signal output valid; component ageCheck = GreaterThan(32); ageCheck.in[0] <== age; ageCheck.in[1] <== ageThreshold; valid <== ageCheck.out * isKYC; } 

Timeline and What You Get

Development of a complete credential verification system takes 8–16 weeks depending on complexity. The cost is calculated individually after requirements audit. To assess your project, reach out to us for a consultation.

Note what you will receive:

  • Deployable smart contracts (Registry + Verifier) with open source.
  • Verifier SDK (TypeScript) for integration into your protocol.
  • ZK circuits (if required) with audited code.
  • Architecture, deployment, and operation documentation.
  • 3 months of support and refinements per your specification.

Our team's experience: 5+ years in blockchain development, 10+ projects in DeFi, NFT, and identity. We guarantee functionality and passing security audits. Order development and get a reliable verification infrastructure.