What the core does
The core is the regulatory library: the rules a compliant Digital Product Passport must satisfy, written as code. It is open source under Apache-2.0, has no infrastructure of its own (no database, no server, no configuration), and anyone may build on it. Its crates are published on crates.io.
What it gives you
Section titled “What it gives you”- A definition of a passport: its identity, who issued it, what it is made of, the product-group data the regulation requires, and the lifecycle it moves through. The exact shape is in the code, which is the authoritative reference.
- Validation: a passport is checked against its product group’s versioned schema and cross-field rules. This runs locally with no network and no services, and nothing leaves the machine.
- Signing and verification primitives: Ed25519 keys, JSON Web Signatures and the encrypted key store a node signs with. Anyone can verify a passport on their own, without the issuer’s systems and without Odal.
- A lifecycle: draft, published, suspended, superseded, retired and end of life. Every transition is recorded, a published passport never returns to draft, and retirement and end of life are final, so a passport’s history cannot be rewritten unnoticed.
- The EU instrument catalog: which acts reach which product group, whether each requires a passport, and from when, with every date marked as read from the text or assumed. The website’s regulations page shows it.
- Access control: which reader may see which part of a passport, and the verifiable credentials that prove a reader’s role.
- GS1 Digital Link, Asset Administration Shell and registry types: what a passport needs to be resolved from a barcode, read by Industry 4.0 systems and registered with the EU.
- Calculators: carbon footprint, repairability and recycled-content calculations, each with a receipt of the method and version used, published for anyone to use.
- The plugin SDK: how a product group’s rules are written as a sandboxed plugin. See Product groups & plugins.
Why it has no infrastructure
Section titled “Why it has no infrastructure”The core stays free of infrastructure so that the line between core and engine holds: code that needs a database or a network belongs in the engine, not in the core. It also means the same rules run unchanged anywhere, from a server to an edge runtime.
Read next
Section titled “Read next”- Standards & interoperability: the open standards a passport uses.
- Product groups & plugins: how each product group’s rules are added and updated.
- Security & cryptography: how a passport is signed and checked.
Information on this site is not legal advice. Legal noticePrivacy policy