Demo ModeExit Demo
← Back to Academy

Credentials & Permissioned Domains 101

On-ledger credentials and permissioned domains (XLS-70/80) — how regulated markets verify who you are without a centralized gatekeeper.

1. What Are On-Ledger Credentials?

A credential (XLS-70) is a verifiable claim recorded directly on the XRP Ledger — for example, that a wallet belongs to an accredited investor or a KYC-verified business. Because it lives on-chain, anyone can check whether a credential is valid without contacting the issuer directly.

2. Issuers, Holders & Verification

An issuer is the entity that creates and vouches for a credential — a regulator, exchange, or compliance provider. The holder is the wallet the credential is attached to. Verification just means checking the credential is present, unexpired, and issued by a trusted issuer, all directly on-ledger.

3. Permissioned Domains Explained

A permissioned domain (XLS-80) is a ledger-level access rule set: only wallets holding specific credentials can participate in that domain's markets or trading pairs. It's how regulated financial products can exist natively on a public blockchain.

4. Why This Matters for Regulated Trading

Traditional compliance means trusting an off-chain database that could be wrong or tampered with. Credentials and permissioned domains move that trust on-chain, so eligibility checks are auditable and enforced by the protocol itself, not by a single company's internal systems.

5. Issuing a Credential (walkthrough)

From the Credentials page, an authorized issuer selects a holder address, chooses a credential type, and submits the issuing transaction for the holder's wallet to sign acceptance. Once accepted, the credential is queryable by anyone checking that address.

6. Domain Membership Management

Domain owners add or remove which credential types grant entry to their permissioned domain. XYZ Wallet's domain membership view shows which domains a wallet currently qualifies for, based on its current credentials.

7. Revocation & Expiry

Credentials can carry an expiration date, and issuers can revoke them before that date if circumstances change (for example, a KYC status lapses). A revoked or expired credential immediately loses any permissioned-domain access it granted.

8. Credentials + Compliance: How They Connect

Credentials give XYZ Wallet's compliance engine a stronger signal than off-chain screening alone — a wallet with a valid, unexpired KYC credential is verifiably different from one with none. Expect credential status to factor into future risk-scoring refinements.

Glossary

Credential (XLS-70)
A verifiable, on-ledger claim about a wallet, issued and vouched for by a trusted issuer.
Issuer
The entity that creates and vouches for a credential.
Holder
The wallet a credential is attached to.
Permissioned Domain (XLS-80)
A ledger-level access rule restricting participation to wallets holding specific credentials.
Domain Membership
Whether a given wallet currently qualifies for a specific permissioned domain.
Revocation
An issuer invalidating a previously issued credential before its expiry.

Quiz

7 of 10 correct to pass and earn 🎓 Credentials Certified.

1. What is an XRPL credential (XLS-70)?
2. Who vouches for a credential?
3. What does a permissioned domain (XLS-80) restrict?
4. Why record eligibility checks on-chain instead of an off-chain database?
5. What must a holder do when a credential is issued to them?
6. Who controls which credential types grant entry to a permissioned domain?
7. What happens when a credential expires?
8. Can an issuer revoke a credential before its expiry date?
9. What advantage do credentials give XYZ Wallet's compliance engine?
10. Where in XYZ Wallet do you manage credential issuance and domain membership?
Go to Credentials