Inspiration
Indonesia produces ~1.7M graduates per year, yet trust is broken. Kemendikbudristek shut down 40 private campuses in 2022-Q1 2023 for jual-beli ijazah and fictitious lectures. ResumeLab (n=1,914) found 70% lie on resumes, StandOut CV (n=2,102) found 64.2% lied at least once, ResumeTemplates (n=9,133) found 96% of 2024 fraudsters were never caught. Meanwhile World Bank/ILO reports 13.08% youth unemployment (2024) and BPS reports 20.31% NEET — ~9M youth idle, 2.49M aged 20-24 jobless. Honest students lose to fakes, SMEs pay $30-150 and wait 3-14 days for manual checks. Permendikbudristek No.58/2024 proves the state sees this as urgent with centralized diploma numbers — but central DBs remain slow, siloed, and insider-mutable.
What it does
VeriCred - Decentralized Credential Passport is a hybrid Web2 + Web3 + AI verifier:
- Issuers (campus/LPK) issue signed credentials: SHA-256 hash + encrypted PDF pinned to IPFS, anchored in a Polygon Amoy smart contract with revoke + expiry.
- Students own via SIWE wallet login, share via QR link.
- Employers verify in 3s at /verify/[id] with no wallet: Valid / Revoked / Hash-Mismatch + AI forgery score. No token, no DeFi. Blockchain is pure trust infrastructure.
How we built it
Phase 1 is conceptual only — no final code yet, per Hacksphere rules. Our validated architecture for the 24h Phase 2 build:
- Frontend: Next.js 14 + Tailwind + RainbowKit/Wagmi + Ethers v6
- Auth: SIWE EIP-4361 + session JWT, no passwords
- Contract: Solidity 0.8.24 CredentialRegistry (issueCredential, revoke, isValid) on Polygon Amoy, Hardhat + OpenZeppelin, verified on Polygonscan
- Storage: IPFS via Pinata, CID equality = tamper proof
- Backend: Node API + Prisma + Postgres (Neon) as indexer cache, PII encrypted off-chain (UU PDP No.27/2022 compliant)
- AI: Featherless AI API (Llama-3 + OCR/layout) for forgery risk + CV parsing
- Deploy: Vercel + Amoy + IPFS gateway, public GitHub with 24h commit history. Live URL > localhost.
Challenges we ran into
Designing for 24h forced hard cuts: no native app, no ZK-proofs, no multi-chain for MVP. Key risks and fixes: Amoy faucet downtime -> fallback Base Sepolia + Hardhat log; Pinata rate limits -> Web3.Storage backup; Featherless quota -> cached + rule-based OCR fallback with live call still shown; wallet UX for non-crypto judges -> gasless verify page + 1-click burner wallet; privacy -> only hashes on-chain, keys destroyable on revoke.
Accomplishments that we're proud of
Data-driven proposal grounded in Kemendikbudristek, BPS, World Bank, and 3 hiring-fraud datasets; minimal auditable contract surface (~120 lines, no payable); 5-click demo where every success path reads chain + IPFS live — judges can paste any CID to test failure; sponsor-aligned AI choice; pilot scoped to President University + 2 SMK + 20 SMEs in Cikarang.
What we learned
Centralized verification fails because attestation, storage, and audit live on one server. Separating them — issuer signature + IPFS content-address + public ledger ordering — restores trust without tokens. AI should advise, not auto-reject. Feasibility beats features in a 24h marathon.
What's next for VeriCred - Decentralized Credential Passport
If Top 30: build exactly this spec in 24h Oct 10-11, freeze, live pitch with tamper-test. Then 12-mo pilot: 500 passports, 2000 credentials, <5s verify, 0 red-team forgeries, 30% faster hiring in 10 SMEs. Revenue: freemium SaaS (100 free/mo, Pro + API). Scale pattern to STR/SIP licenses, halal certs, surat keterangan desa. Build·Muse Spark 1.3 FreePersonal / OpenCode·medium ~
Built With
- featherless-ai
- hardhat
- ipfs
- next.js
- node.js
- pinata
- polygon
- postgresql
- siwe
- solidity
- tailwind
- vercel
- wagmi
Log in or sign up for Devpost to join the conversation.