Registration Certificate
The Access Certificate proves who you are. The Registration Certificate is easy to misread as proof that you're allowed to ask for data — it is not. Its actual job is narrower and, in some ways, more important: it makes your reason for asking transparent and publicly attributable.
Not an authorization — a transparency mechanism
The Registration Certificate is not permission. The Registrar does not judge, vet, or approve whether your stated purpose is legitimate. What it does is sign your public declaration of why you intend to interact with a wallet — so that this declaration is on record, attributable to your organization, and checkable by others.
Before you can ask a wallet for data, you must declare, in the Registrar, what you intend to use the interaction for. That declaration becomes part of a queryable registry entry tied to your organization. The Registration Certificate is simply the Registrar's signature over that declaration — confirmation that this specific reason was made transparent, not an endorsement that the reason is good, proportionate, or lawful. That judgment is left to others.
Why this matters: accountability, not gatekeeping
Because these declarations are recorded and queryable, they can be checked after the fact — by supervisory bodies, journalists, or civil-society organizations such as NGOs — against what an organization is actually doing in practice. If a Relying Party's real-world data requests do not match what it declared, that mismatch becomes visible and can be challenged. The Registration Certificate is what makes that kind of external scrutiny possible at all: without a signed, public declaration of intent, there would be nothing to check requests against.
This is also why skipping or falsifying it is not a minor technicality. The Registrar signing your declaration is what allows the wallet to know that the reason you gave was actually put on the record — not invented on the spot, purely for that one request, with no accountability attached.
Who issues it, and how you get one
The Registration Certificate is issued by the same Registrar that issues your Access Certificate, as part of the same registration process — there is no separate Know Your Business check to complete for it. Declaring your purpose to the Registrar and legitimizing your organization happen together; you receive both certificates as a pair.
What you receive
Both certificates from the Registrar work together, and your systems need both:
- The Access Certificate — proves who you are. See What is the Access Certificate?
- The Registration Certificate — proves your stated purpose was transparently declared and signed
Neither is optional or interchangeable with the other. Leaving out the Registration Certificate does not make your request "unaccountable but harmless" — it removes the one mechanism that lets anyone outside your organization verify what you said you'd use the data for.
This page explains what the Registration Certificate is and the role it plays. For the technical detail — how it's structured and how to embed it in a presentation request — see Using Registrar Certificates in Presentation Requests.