# Issue with Certificate Upload - "Invalid Credential" Error

**URL:** <https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703>\
**Category:** Uncategorized\
**Created:** [December 17, 2024, 8:45am UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703 "2024-12-17T08:45:52Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [December 17, 2024, 8:45am UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/1 "2024-12-17T08:45:52Z")

</div>

I have used **Cert-tools** to create unsigned certificates and **Cert-issuer** (with Ethereum) to generate [signed certificates](https://raw.githubusercontent.com/sreenumalae/DataStorage/refs/heads/main/signedcert.json).

However, when I upload the signed certificate to the app, I encounter the following error:  
**“Invalid Credential”**

I would appreciate any guidance on resolving this issue.

Additionally, I would like to know:

1. How to generate the **Issuer URL**?
2. How to generate a **one-time code** for the certificates?

Thank you for your help!

@lemoustachiste

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [December 18, 2024, 8:31am UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/2 "2024-12-18T08:31:49Z")

</div>

The error should be visible in the browser console.

Your issuer URL should be the URL of your issuer profile. It can be a DID. You can look at a hybrid profile here: [https://www.blockcerts.org/samples/3.0/issuer-blockcerts.json](https://www.blockcerts.org/samples/3.0/issuer-blockcerts.json)

Your issuer profile should reference a public key listed in `verificationMethod` and available in say `assertionMethod`.

That same key should be used in the `proof.verificationMethod`.

That key should be presented in such format (JWK is fine) that the verifier can transform the public key into the issuing address used for the blockchain network of the transaction.

You should host your document somewhere accessible from the web (no CORS).

> How to generate a **one-time code** for the certificates?

I’m not sure what you mean by this.

---

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [December 18, 2024, 8:47am UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/3 "2024-12-18T08:47:46Z")

</div>

@lemoustachiste

Thanks for the quick response  
Regarding the onetime code and issuer url the following forum help me alot

> [@Learning Machine Contributes Android App to Blockcerts](https://community.blockcerts.org/t/learning-machine-contributes-android-app-to-blockcerts/227/12):
>
> Hi @gowtham, the following steps are for adding an issuer. You need to create your issuer JSON like this [https://issuer.growbit.xyz](https://issuer.growbit.xyz) take in mind that the image in the JSON is visibile in the Blockcerts app. The JSON key introductionUrl value should be a public HTTP endpoint. When the user, on the Blockcerts app, click on Settings and then Add Issuer he need to insert as Issuer Url [https://issuer.growbit.xyz](https://issuer.growbit.xyz) (the location of issuer JSON) and optionally an OTP. When the user confirm the Blo…

However i just want to know can i verify the certificate which i generated using ethereum in android-wallet and ios-wallet ?

Is ios-wallet accepting V3 certificates ?

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [December 18, 2024, 2:02pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/4 "2024-12-18T14:02:33Z")

</div>

Yes, both apps are compatible with v3

---

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [December 19, 2024, 10:10am UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/5 "2024-12-19T10:10:16Z")

</div>

@lemoustachiste  
But when i try to validate [certificate](https://raw.githubusercontent.com/sreenumalae/DataStorage/refs/heads/main/7b553bc8-da76-4389-ba33-b9a33269aacf.json) it works well in [site](https://www.blockcerts.org/)

But when i try to validate the same certificate in the mobile i’m facing an error as show in the image

 ![shared image](https://us1.discourse-cdn.com/flex016/uploads/blockcerts/original/1X/a949e6bcf32536832b10b4259b75a4b0bfbb5647.jpeg)

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [December 19, 2024, 12:49pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/6 "2024-12-19T12:49:32Z")

</div>

Just to confirm, this is the Android app, latest version?

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [December 19, 2024, 1:03pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/7 "2024-12-19T13:03:54Z")

</div>

I have replicated the issue, I will take a deeper look at it.

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [December 19, 2024, 2:41pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/8 "2024-12-19T14:41:29Z")

</div>

Hey,

so I believe I have found the issue.

If you pull up [JSON-LD Playground](https://json-ld.org/playground/) and paste your certificate in, then take a look at the `canonized` tab, you’ll see a safe mode error, which means that this property didn’t get properly hashed when issuing (last time I checked the pyld library safe mode wasn’t implemented so it’s not failing at issuance time).

You’ll need to define the key `college` as a jsonld object into your context and issue again.

The fact that it passes on [blockcerts.org](http://blockcerts.org) is more the bug than the other way around so I’m looking into that.

---

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [January 20, 2025, 6:46pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/9 "2025-01-20T18:46:30Z")

</div>

Hey @lemoustachiste

I addressed the issue you previously mentioned regarding the college and have [issued a new certificate](https://raw.githubusercontent.com/sreenumalae/DataStorage/refs/heads/main/1c91ae12-3a76-47d6-9101-45f43cf1ecdd.json). The JSON file for the certificate has been validated in the [JSON-LD Playground](https://json-ld.org/playground/), and no errors were detected there. Additionally, I didn’t encounter any errors in Blockcerts.

However, when I try to verify the same certificate using [cert-verifier-js](https://github.com/blockchain-certificates/cert-verifier-js), I’m still facing the following issue:  
**“Merkle root does not match remote hash.”**

Could you please help me understand why this discrepancy might be occurring? Let me know if you need any additional details or files to investigate further.

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [January 21, 2025, 12:24pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/10 "2025-01-21T12:24:29Z")

</div>

Have you re-issued the credential with the new context? The proof value can change because the normalization is different due to the new keys that were specified, so if you modify your context you will need to re-issue all credentials bound to that context.

---

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [January 21, 2025, 1:17pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/11 "2025-01-21T13:17:39Z")

</div>

Yes i have re-issued the credential yesterday

I have created the new template and created unsigned certificate using cert-tools and issued the signed certificate using cert-issuer.

[Here is my new certificate](https://raw.githubusercontent.com/sreenumalae/DataStorage/refs/heads/main/1c91ae12-3a76-47d6-9101-45f43cf1ecdd.json)

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [January 21, 2025, 3:48pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/12 "2025-01-21T15:48:17Z")

</div>

I think you need to look at what’s being serialized in the jsonld playground, in cert-issuer ([cert-issuer/cert\_issuer/normalization\_handler.py at master · blockchain-certificates/cert-issuer · GitHub](https://github.com/blockchain-certificates/cert-issuer/blob/master/cert_issuer/normalization_handler.py#L13)) and cert-verifier-js (technically it’s in the MerkleProof package: [jsonld-signatures-merkleproof2019/src/inspectors/computeLocalHash.ts at master · blockchain-certificates/jsonld-signatures-merkleproof2019 · GitHub](https://github.com/blockchain-certificates/jsonld-signatures-merkleproof2019/blob/master/src/inspectors/computeLocalHash.ts#L74)).

You’ll need to run local copies to be able to print out the results and this tool is useful for comparing texts: [https://text-compare.com/](https://text-compare.com/)

I’m sorry I don’t have more time to do it myself.

---

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [January 28, 2025, 6:06pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/13 "2025-01-28T18:06:42Z")

</div>

Hi @lemoustachiste

 ![Screenshot 2025-01-28 at 11.31.51 PM](https://us1.discourse-cdn.com/flex016/uploads/blockcerts/original/1X/38c3f5e5d0b81f4fc53c972e4bd68ea31ed20a0a.jpeg)  
I have printed the normalizedDocument in both [cert-issuer](https://github.com/blockchain-certificates/cert-issuer/tree/master) and [jsonld-signatures-merkleproof2019](https://github.com/blockchain-certificates/jsonld-signatures-merkleproof2019/tree/master)  
and seems both texts are identical and i still face the **Merkle root does not match remote hash** error.

For your refere

```auto
<ecdsa-koblitz-pubkey:mkwntSiQmc14H65YxwckLenxY3DsEpvFbe> <http://schema.org/alumniOf> <https://www. **********.com/> .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <http://schema.org/keywords> "AI/ML/BigData" .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <https://w3id.org/blockcerts#BlockcertsCredential> .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <http://www.w3.org/1999/02/22-rdf-syntax-ns#type> <https://www.w3.org/2018/credentials#VerifiableCredential> .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <https://w3id.org/openbadges#salt> "47a8406b-0ad8-4dc8-bd04-8b5653bcd592" .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <https://w3id.org/security#nonce> "E17WPV96CM" .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <https://www.w3.org/2018/credentials#credentialSubject> <ecdsa-koblitz-pubkey:mkwntSiQmc14H65YxwckLenxY3DsEpvFbe> .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <https://www.w3.org/2018/credentials#expirationDate> "2025-01-21T18:09:45Z"^^<http://www.w3.org/2001/XMLSchema#dateTime> .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <https://www.w3.org/2018/credentials#issuanceDate> "2025-01-20T18:34:04Z"^^<http://www.w3.org/2001/XMLSchema#dateTime> .
<urn:uuid:f6c56398-1b50-4eb1-b423-b1595fa442f8> <https://www.w3.org/2018/credentials#issuer> <https://raw.githubusercontent.com/sreenumalae/DataStorage/main/issuer.json> .

```

---

<div class="post-metadata">

**Author:** ![sreenumalae](https://sea2.discourse-cdn.com/flex016/user_avatar/community.blockcerts.org/sreenumalae/32/773_2.png) [@sreenumalae](https://community.blockcerts.org/u/sreenumalae)\
**Post date:** [January 28, 2025, 6:40pm UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/14 "2025-01-28T18:40:12Z")

</div>

@lemoustachiste

I am currently using the Ethereum testnet Sepolia.

From my debugging, I noticed that the remote hash is undefined.

This suggests that the Ethereum testnet Sepolia API might not be working as expected.

After i updated the following code everything works as smooth

```auto
function getTransactionServiceURL$1(chain) {
      const baseUrl = getApiBaseURL$1(chain);
      if(chain =="ethsepolia"){
        return `${baseUrl}&action=eth_getTransactionByHash&txhash=${TRANSACTION_ID_PLACEHOLDER$2}&apikey= ***YOUR_API_KEY**** `;
      }
      else{
        return `${baseUrl}&action=eth_getTransactionByHash&txhash=${TRANSACTION_ID_PLACEHOLDER$2}`;
      }
  }

```

We need to add the api key if the chain is ethsepolia while getting the remote hash.

---

<div class="post-metadata">

**Author:** ![lemoustachiste](https://avatars.discourse-cdn.com/v4/letter/l/7c8e57/32.png) [@lemoustachiste](https://community.blockcerts.org/u/lemoustachiste)\
**Post date:** [April 9, 2025, 6:45am UTC](https://community.blockcerts.org/t/issue-with-certificate-upload-invalid-credential-error/3703/15 "2025-04-09T06:45:52Z")

</div>

Hi @sreenumalae,

could you maybe open a pull request on explorer-lookup with this fix?
