DEV Community

Cover image for Dog Passport: a soulbound vaccination record your vet signs, on Solana
Pentine Pejay
Pentine Pejay Subscriber

Posted on

Dog Passport: a soulbound vaccination record your vet signs, on Solana

DEV Weekend Challenge: Dog Days Edition Submission 🐕

This is a submission for Weekend Challenge: Dog Days Edition

What I Built

Dog Passport turns a dog's vaccination and pedigree record into a
non-transferable Token-2022 on Solana that the issuing vet signs with their own
keypair.

A boarding kennel, groomer, border agent, or a new owner can open the passport,read it straight from the chain, and see two things at once: the dog's details,and whether the record was really signed by a known vet. No app account, no central server to trust, no company that can shut down and take the records with it. The token is soulbound, so it stays bound to the dog and cannot be sold or swapped like an NFT.

The problem is small and real. Paper vaccination cards get lost right when you need them for boarding or travel. Pet-record apps die with the company that made them. Breeders hand over pedigrees you have no way to check. A vet-signed on-chain record fixes the parts that hurt: it is portable, tamper-evident, and outlives any single vendor.

The passport carries a photo, passport number, owner, breed, date of birth, colour, microchip, the vaccination history, and the issuing vet's key. Every one of those fields, including the photo, is covered by the vet's signature.

passport

Demo

Live (Solana devnet, no wallet or setup needed):

The landing page has a gallery of five real dogs plus two test states, so you can click through every verification outcome:

Viewer

  • Authentic — signed by a trusted vet. Green "VERIFIED" stamp, all checks pass.
  • Untrusted issuer — a valid signature from a vet who is not in the trusted list. Amber stamp.
  • Tampered — a field was altered on-chain after signing, so the signature nolonger matches. Red "INVALID" stamp.

verification-untrasted

tampered

The viewer renders a proper passport data page: photo, fields, a machine-readable zone, per-vaccine validity status (up to date, due soon, overdue), a verification checklist, and a QR code of the shareable link. It can also scan a printed passport QR with the device camera.

overdue

Open the live link above and click the gallery chips to see each outcome for yourself, straight from devnet.

The verification is honest. Change any field in the record and the signature no longer matches:

original verifies  : true
tampered breed     : false
tampered vaccine   : false
wrong issuer key   : false
Enter fullscreen mode Exit fullscreen mode

Code

Dog Passport

A dog's vaccination and pedigree record issued as a non-transferable Token-2022 on Solana. A vet signs each record with their keypair, so a boarding kennel groomer, border agent, or new owner can verify the record is authentic and came from a specific vet, without trusting any central server or app.

Runs on Solana devnet.

Why on-chain

Paper vaccination records get lost. App-based pet records die when the app or company shuts down. A breeder can hand you a pedigree with no way to check it. Putting the record on-chain as a soulbound token makes it portable, tamper-evident, and independent of any single vendor. The passport is bound to the dog, not tradeable, so it cannot be sold or swapped like an NFT.

How it works

Each passport is one Token-2022 mint with three extensions:

  • NonTransferable — the token is soulbound. Once minted to the owner it cannot be…

How I Built It

Stack: plain @solana/web3.js + @solana/spl-token, no Anchor program. A handful of Node scripts plus a static viewer, small enough to build and verify in a weekend.

The Solana part that matters. Each passport is one Token-2022 mint that combines three SPL Token Extensions:

  • NonTransferable makes the token soulbound. I de-risked this first with a proof-of-concept that mints a token and then tries to transfer it. The program rejects the transfer, which is exactly what a passport needs.
  • MetadataPointer points the mint at itself for metadata, so there is no separate metadata account.
  • TokenMetadata stores the whole record on-chain in additionalMetadata:passport number, name, breed, dob, sex, colour, microchip, owner, photo URL andits SHA-256 hash, the vaccine list, the issuing authority, the vet's public key, and the vet's signature.

solana

metadata

Issuer-signed records. The value is not "data on a chain," it is who signed it. The vet holds an Ed25519 keypair. Before minting, the vet signs a canonical serialization of the record (stable key order, reproducible byte-for-byte) with tweetnacl. That detached signature goes on-chain. Verification recomputes the canonical record from the on-chain fields, checks the signature against the vet's
public key, then checks that key against a trusted-vet list. Tampering fails because the bytes being verified no longer match the bytes that were signed.

Photo integrity. The image is bound to the record by hashing its bytes and signing the hash. The viewer re-hashes the photo it displays and compares, so the picture cannot be swapped without breaking verification.

The viewer and hosting. The on-chain read and the verification run in one loadAndVerifyPassport function shared by the CLI and the web. On Vercel it runs as a serverless function at /api/passport; locally the same function runs behind a small Node server. The function is host-agnostic: it reads the photo and the trusted-vet list over HTTP from its own deployment, so nothing from the local
filesystem has to be bundled.

Two things that fought back. The public devnet faucet was rate-limited to death, so funding falls back across endpoints (an Alchemy demo endpoint saved the day). And on Vercel, @solana/web3.js pulls in rpc-websockets, which bundles an ESM-only uuid and then require()s it, crashing the function with ERR_REQUIRE_ESM; pinning uuid to its CommonJS build via an npm overrides fixed it.

Prize Categories

Best Use of Solana. - Used Token-2022's NonTransferable extension to make the passport soulbound, on-chain TokenMetadata to carry the record, and the issuer-signature model to make verification about the vet rather than a server.

What's next

  • Real vet identity: a registry or attestations instead of a local trusted list.
  • An owner-transfer flow for rehoming and adoption, without making the token freely tradeable.
  • Mainnet custody and a kennel/border scanner app.

Top comments (0)