Skip to main content
GIWA Dojang Dojang (도장, the seal) is GIWA’s attestation service: trusted off-chain facts issued as on-chain attestations, with zero PII on-chain. It is built entirely on Ethereum Attestation Service (EAS), deployed at the standard OP Stack predeploy slots, with a GIWA issuer and schema framework on top. The key design property: identity lives as attestations about an address, never as tokens owned by an address. That makes Dojang credentials non-transferable by construction, the exact property ERC-8004 lacks, and Dojang gets it for free. This is the same property the Builder Passport inherits.

Attestation types

Tokscale’s Usage Root design borrows the Balance Root / Verified Balance pattern directly: a public commitment with private per-user proofs. See Evidence Ladder.

Contract architecture (public GIWA Sepolia, chain ID 91342)

EAS itself sits at the OP Stack predeploy slots, permissionless. GIWA’s framework sits on top. All addresses below are live on public GIWA Sepolia: The documented Verified Address schema UID is 0x072d75e18b2be4f89a13a7147240477481c4b526d5795802acba59046b426e08 and its schema text is bool isVerified. Reading a Verified Address result is one call to DojangScroll.isVerified, and GIWA’s docs ship a ~10-line onlyVerified Solidity modifier. Attester IDs are namespaced (keccak256("dojang.dojangattesterids.<issuer>")), making the system multi-issuer by design; external issuers are explicitly invited.

The three permission lanes

Archived GIWA Testnet Faucet compatibility fixture

On GIWA Sepolia, the DojangAttesterBook resolves the documented Testnet Faucet attester ID to 0x63CCe2b569A7bC35895ee24306c1512fefc06121. Tokscale retains one block-pinned read-set against this public attester as an interoperability regression fixture: it proves that our validator can read GIWA’s existing Verified Address graph end to end. It is archived test evidence, not a Tokscale issuer credential. It is not rendered on the public disclosure page, has no public product API, and does not represent a Tokscale KYC claim or official issuer status.

Tokscale’s read-vs-publish split

Read side (delivered, read-only). Tokscale consumes deployed Dojang as provenance through a fail-closed validator: it requires the complete GIWA Sepolia read set at one pinned block, rechecks the block hash, pins the EIP-1967 implementation slots, and verifies the schema fingerprint and the EAS record behind any isVerified result. DojangScroll.isVerified alone is never treated as sufficient. The API contract carries informationalOnly: true, so an observation cannot become a payment or entitlement authority. Tokscale does not deploy Dojang contracts and is not a Dojang issuer.

Owner verification and Passport visibility

The console’s live verification belongs to the exact GIWA Sepolia wallet that authenticated the session. It is not an account-wide badge. A linked wallet cannot stand in for the signed-in wallet, and a session without wallet authentication does not request or refresh Dojang evidence. A refresh asks a server worker to make one bounded observation at a finalized block. The worker accepts a positive result only after it checks the pinned policy, contract graph, issuer, schema, and EAS attestation. It records either a verified or unverified observation for that wallet. It never converts a reader failure into an unverified result. The contract keeps that observation separate from Passport visibility. An observation is publicly visible only when it belongs to the exact active Passport publication for the same wallet, wallet epoch, and policy version. Republish, wallet replacement, or a policy change creates a new publication boundary. Evidence from an earlier publication remains private and cannot appear on the new public Passport by accident. The owner view therefore reports both facts: the observation and whether it is public, awaiting an observation for the current publication, attached to another published wallet, or private because there is no active Passport publication. This preserves the reader-facing distinction between a missing attestation and a missing trustworthy observation. The deployed-read check is a bounded, block-pinned observation (fixture block 31129890), run by an operator with a caller-supplied RPC. It sends no transaction and needs no key:
A read-set or attestation mismatch fails the run; a missing endpoint exits as a skipped external validation. It proves the deployed Dojang graph and the public Testnet Faucet attestation at that one block; it is not evidence of a continuously available live integration. Publish side (permissionless). Anyone can register schemas and attest on EAS. Tokscale’s schema set (Usage Root mirroring Balance Root, Verified Usage mirroring Verified Balance, Skill Signal, Bounty Completion) follows Dojang’s own commitment idiom. The first Usage Root is now anchored on public GIWA Sepolia; see Usage Root EAS integration-test attestation below.
Local and public are never mixed. The local fixture (LocalDojangScroll) is sealed and deterministic; local artifacts are never shown next to Sepolia explorer links. Anvil borrows chain ID 91342, so chain ID is not a network identity; see Network Separation.

The Phase 2 path: official issuer

Phase 2 registers Tokscale in the DojangAttesterBook as an official issuer, under the attester ID keccak256("dojang.dojangattesterids.tokscale"), after GIWA approval. Until then, Tokscale’s public EAS records are permissionless application attestations, not official Dojang issuer evidence. Once approved, this page and the public disclosure will show the registered attester ID and the first official issuer attestation separately from the testnet record below.

Usage Root EAS integration-test attestation

Tokscale’s first public Usage Root is anchored on GIWA Sepolia (chain ID 91342). It is a real attestation published by Tokscale’s disposable one-time test attester under an application-defined, permissionless EAS schema. It commits a Merkle root over a frozen three-receipt integration-test vector, mirroring Dojang’s Balance Root idiom. The public disclosure page labels this record Usage Root EAS integration-test attestation. It demonstrates the complete publish-and-read path under a Tokscale-owned schema without claiming that Tokscale is a GIWA Dojang issuer. The record is fixture-backed: its recipient is a test-vector subject, and it is not a Verified Address, identity credential, KYC result, wallet-ownership claim, or production-usage record. Anyone can confirm the anchor independently against the public RPC, with no key and no transaction:
The canonical record is checked into the Tokscale GIWA repository. The attester key is a disposable one-time testnet signer; this anchors a real public test vector, not a production identity or usage authority.

Next steps

  • For the Tokscale schema that mirrors Dojang’s Balance Root, see Receipt Attestation.
  • For the credential Dojang is meant to gate, see Builder Passport.
  • For the full address list including GIWA’s own Dojang contracts, see The Public Chain.
  • For why an anonymity-first design cannot run on this chain, see Why GIWA.