Inspiration

A student's proof of work is scattered: a Python certificate in one inbox, a hackathon result on another site, projects on GitHub, an internship letter as a PDF. A recruiter has no fast way to tell which of these are real. Colleges verify documents by hand, and students often can't tell which skills their target career still needs.

We wanted a fix built on one rule: an AI's opinion is not proof. Attesta separates what software suggests from what an issuer has actually confirmed.

What it does

Attesta is a verifiable skill passport for students.

  • Students upload certificates, add projects and GitHub links, see their skills as a graph, pick a target role, and get a gap analysis. They share a public profile by link or QR code.
  • Issuers (colleges, companies, organizers) confirm and issue credentials, and can revoke them.
  • Recruiters scan a QR code and see every credential in one of three states: AI-extracted (unverified), Issuer-verified, or Revoked or tampered.

How we built it

Five agents work behind the interface:

  1. Evidence Verification Agent extracts the title, issuer, date and credential ID, and flags missing or suspicious fields.
  2. Skill Graph Agent maps evidence to a standard skill taxonomy.
  3. Career Mentor Agent compares verified skills with a target role and suggests projects and priorities.
  4. Integrity Agent is plain deterministic code with no LLM. It hashes the file and checks it against the chain.
  5. Profile Agent writes summaries using only facts present in the profile.

A credential counts as verified only when

$$ \text{SHA-256}(d) = h_{\text{chain}} \ \wedge\ \neg\,\text{revoked} $$

where $d$ is the uploaded document and $h_{\text{chain}}$ is the hash stored by the issuer. Changing a single byte of $d$ changes the hash completely, so tampering is detected.

Stack: React, Vite, Tailwind and React Flow on the front end; FastAPI, Pydantic and SQLAlchemy on the back end; a Solidity contract (VerifiableCredentialRegistry) tested with Hardhat and used through Ethers.js. OCR uses pdfplumber with a Tesseract fallback. The AI layer validates strict JSON output and has a deterministic fallback, so the app still works without an API key.

Why blockchain: several independent issuers write records, and any recruiter can check them without trusting our servers. The chain stores only the credential ID, document hash, issuer and recipient addresses, timestamp and revocation flag. No PDFs, names, emails or ID numbers ever go on-chain.

Challenges we ran into

  • Keeping AI and verification apart. It was tempting to let a confident extraction look like proof. We made the three status labels a fixed part of the UI and API.
  • Messy documents. Certificates come in different layouts and scan quality, so extraction is imperfect. That is why every AI result is marked unverified until an issuer confirms it.
  • Privacy on a public ledger. We had to decide exactly what may be stored on-chain, and keep everything else off it.
  • Wallets for students. Most students have no wallet, so the backend generates recipient addresses and MetaMask stays optional.

What we learned

  • Blockchain is useful when several parties who don't trust each other need a shared record. Here it is only a tamper-evident registry, not a token or a speculation tool.
  • Agents are more convincing when each has a schema, a confidence score and an audit-log entry, and when the critical check involves no LLM at all.
  • A demo that runs end to end (upload, verify, tamper, fail, revoke) says more than a long feature list.

What's next

IPFS storage, deployment to a public testnet, bulk issuance for colleges, and a recruiter API.

Revenue model

Students use it free. Issuers pay per issued credential or through an annual institutional plan. Recruiters pay for bulk verification and candidate search. The core stays open source, and revenue comes from the hosted service and support.

Built With

Share this project:

Updates

Submission history