When someone presents a digital document issued by another country, proving that the document is authentic is only the beginning.
Suppose Inés, a Brazilian accountant, moves to Montevideo and needs to complete a procedure through a Uruguayan government portal. She has a digital identity issued by Brazil and a digital university degree issued by a Brazilian university.
Uruguay can verify the signatures on those documents. But before accepting them, it needs to know something else: who is behind that signature, and why should Uruguay trust that institution?
It also needs to know whether the way Brazil verified Inés’s identity meets Uruguay’s requirements, and how the systems in both countries can exchange the information they need.
Until now, much of this work has been handled through agreements between governments and institutions, specific integrations, and lists of recognized authorities. Verifiable credentials allow part of that trust to become digital infrastructure. This is where Propia comes in.
In April, we explained how an organization can verify a credential without contacting the organization that issued it. Now we take that one step further: what does a government need to know before accepting a credential issued outside its own system, and how can that trust become something systems can query directly?
1. First, you need to know who can issue
Start with Inés’s degree.
Her university can issue a digital credential stating that she earned her accounting degree. The university digitally signs the credential using a key it controls.
When Inés presents it in Uruguay, the receiving organization can verify that the signature is valid and that the document has not been altered.
But that still leaves a fundamental question:
How does Uruguay know that the key actually belongs to a university authorized to issue degrees?
The traditional answer is an agreement or a trusted list. Uruguay could maintain a list of Brazilian universities it recognizes, or the two countries could agree on which authorities are valid.
The problem emerges as this model has to scale. There are more countries, more institutions, more issuers, and more keys. Maintaining trust relationships one by one becomes difficult.
Propia proposes turning this information into a trust layer that systems can query directly.
Instead of requiring every verifier to maintain its own list, Propia proposes a public registry where systems can check which issuers are recognized and which credentials they are authorized to issue.
So when Uruguay receives Inés’s degree, it can verify not only that the signature is valid, but also that the institution behind the signature is recognized as a valid issuer.
2. Then, you need to know what “verified” actually means
Inés’s identity presents a different problem.
Brazil and Uruguay may use different procedures to establish that someone is who they claim to be. One country may verify an identity entirely online, while another may require an in-person appearance, official documents, or biometric checks.
That is why it is not enough to say that Brazil “verified” Inés. Uruguay needs to know what checks she had to pass.
Identity systems address this through assurance levels. Each level represents a set of requirements a person must meet for the system to consider their identity sufficiently trustworthy.
When two countries want to recognize each other’s identities, they need to establish which assurance levels they accept.
Uruguay and Brazil have already done this. According to Agesic, Uruguay considers Brazil’s highest level, known as gold, equivalent to its own advanced level.
This allows people with a Brazilian gold-level identity to access more than 400 digital services in Uruguay, under the assurance conditions agreed between the two countries.
In this case, recognition remains a government-to-government agreement. Propia addresses another part of the problem: trust in credentials and in the institutions that issue them.
Its model uses public registries to make it possible to check who is authorized to issue, which key the issuer controls, and the current status of a credential.
The result is that trust does not have to depend entirely on a direct integration between the system that issued a document and the system that receives it.
3. Finally, the systems need to be able to talk to each other
There is a third piece: even if Uruguay knows who issued the credential and trusts that issuer, the systems still need a way to exchange it.
This is where interoperability protocols come in.
When Inés signs in using her Brazilian digital identity, the systems in both countries need common rules for requesting and exchanging the information they need.
Her university degree can follow a different path. Inés can store it in a wallet and present it directly to the Uruguayan government organization.
In that case, the wallet and the organization need compatible protocols to request, receive, and verify the credential.
Among the most widely used standards are OpenID4VCI, for issuing credentials, and OpenID4VP, for presenting them. In September, the OpenID Foundation announced the first implementations to pass its public conformance tests.
Sovra builds on these standards so credentials can move between wallets, issuers, and verifiers without every integration having to define its own rules. SovraID enables the issuance and verification of credentials, SovraWallet lets people store and present them, and Propia provides the trust layer for verifying issuers and their credentials.
How it works with Sovra
Let’s go back to Inés’s degree.
The university issues the credential.
With SovraID, the university issues the degree as a digital credential signed with its own key. Its status can be updated later, for example if the credential needs to be revoked.Inés stores the credential.
She stores it in SovraWallet, where she controls her credentials and decides when to present them.Uruguay receives and verifies the degree.
The government organization initiates the presentation through a QR code and cryptographically verifies the credential’s signature. It does not need to contact the university every time Inés presents the degree.Uruguay verifies trust in the issuer.
This is where Propia comes in. The organization can query its registries to check that the university is recognized as an issuer for that type of credential, that the key associated with the issuer remains valid and under its control, and that the credential has the expected status.
The distinction matters.
Credential verification answers: “Is this document authentic?” Propia adds: “Why should I trust the institution that issued it?”
And it does so without turning that trust layer into a database of people. The registries do not need to store Inés’s personal data or record where she presented her degree.
From system-to-system agreements to trust infrastructure
For Inés to complete the procedure in seconds, several pieces have to work together: her identity has to be recognized, the institution that issued her credential has to be trusted, and the systems need to be able to exchange and verify that information.
Government agreements still matter because they determine which identities and authorities each country recognizes. But not everything has to be solved through a direct integration between every pair of systems. An architecture like Propia allows part of that trust to become open, queryable infrastructure, without requiring every organization to build and maintain its own lists and integrations.
That is the shift: the credential can travel with the person, while the information needed to trust it can be available to whoever needs to verify it.
Keep reading
[PODCAST] Ep. 11 with Héctor Saravia: how Peru’s civil registry chose to stay out of every verification of its digital ID.
Digital Credential Wallets: What Changes When They Go Into Production: what a government wallet needs when its documents start circulating to other institutions.
Keep the conversation going
Our knowledge center at sovra.io/knowledge explains verifiable credentials, trust registries, and digital identity standards in plain language, from the basic concepts to the systems already in production.
How does your country decide which foreign identities it accepts? Reply and tell us. We read every response, and if someone on your team works on interoperability, send them this edition.
Subscribe to The Identity Brief, published weekly.




