TECHNICAL REFERENCE · 2026.10

TKAWEN OS

An operating system for training institutions. Each institution gets a complete academy on its own address your-academy.tkawen.com, running on a database of its own, issuing certificates cryptographically signed with its own key — from the first lesson to the verification page.

multi-tenantDB per academyEd25519SCORM 1.2 · 2004xAPI · cmi5 · LRSLTI 1.3ar · fr · en
01 — ANATOMY

Five layers, one request path

Every request enters through the academy's subdomain. The tenant is resolved from that subdomain before anything else, and from then on the request only touches that academy's data.

EdgeOne wildcard TLS certificate for every academy subdomain; routing by hostnginx · *.tkawen.com
AppsThe learner app, and the owner & instructor panelSvelteKit · /manage
Tenant coreAPI that resolves the academy from the host and enforces permissionsLaravel 13
IsolationA database, storage, cache and job queue per academytkawen_<slug>
TrustA signing key pair per academy; the private key stored encryptedEd25519
02 — PROVISIONING

A complete academy in one command — or nothing

Provisioning is not copying a template. One command builds the tenant, its database and tables, the owner account, roles, theme, certificate template and signing key. If any step fails — a database that cannot be created, a migration that does not finish — everything is rolled back: no half-built academy, no account nobody asked for.

acme.tkawen.com
  • database tkawen_acme
  • storage storage/acme
  • queue queue:acme
  • signing key ed25519:acme
nour.tkawen.com
  • database tkawen_nour
  • storage storage/nour
  • queue queue:nour
  • signing key ed25519:nour
atlas.tkawen.com
  • database tkawen_atlas
  • storage storage/atlas
  • queue queue:atlas
  • signing key ed25519:atlas

NO SHARED DATABASE · NO SHARED STORAGE · NO SHARED QUEUE

03 — THE PRODUCT

Three interfaces, each role with its own tools

The owner's panel runs the whole academy, instructors see only their own courses, and learners use the app on desktop and phone. Real screenshots of the demo academy (Arabic interface).

Curriculum builder
a programme page as the learner sees it
Desktop — owner panel: courses, enrolments, payments, instructorsPhone — a programme page as the learner sees it
Curriculum builder

Curriculum builder

Modules, lessons and quizzes, with a sequential lock chosen by the instructor.

Learning room

Learning room

Lesson after lesson; progress recorded on the server.

Enrolments & progress

Enrolments & progress

Each learner's progress and status, with an early warning after 14 days of inactivity.

04 — LEARNING ENGINE

The learning engine

Nine lesson types, seven question types, and a sequential lock enforced by the server, not the interface — nobody skips a lesson by editing a URL.

Video

Audio

Text

PDF

Quiz

Assignment

Live session

SCORM

xAPI · cmi5

Sequential lock

open · prev · prev_pass

7 question types

Single choice, multiple choice, true/false, free text, matching, fill-the-gap, keywords.

Pass mark & attempts

Each quiz has a pass mark and an attempt limit (3 by default), with a gradebook for the instructor.

Early warning

A learner inactive for 14 days surfaces to the instructor before they drop out.

05 — CRYPTOGRAPHIC CERTIFICATES

A certificate that cannot be forged — by mathematics, not by stamp

Nobody types a certificate by hand. It is issued automatically at 100% completion with the final quiz and all assignments passed, then signed with the academy's own Ed25519 key. Changing a single character invalidates the signature, and verification reads the registry — not an image or a PDF.

verify — demo certificate
{
  "status": "valid",
  "code": "TK-LJA74G2Z",
  "holder": "Demo Student",
  "programme": "Git & GitHub",
  "issuer": "Demo Academy",
  "credential_id": "crd_01m2ya21azztz6bmx6esgje3ns",
  "signature": "Ed25519 ✓"
}
Valid certificate

Real screenshot of the demo academy's verification page in English (holder and course names are the demo's Arabic data). 11 certificate designs plus a free designer, in Arabic and English.

06 — STANDARDS

Speaks the language of the world's learning systems

Content authored with standard tools runs as is, learning records are written to an open standard, and the academy opens inside Moodle and sends grades back.

SCORM1.2 · 2004

Runs SCORM packages and records progress and score.

xAPIExperience API

xAPI statements stored in a Learning Record Store per academy.

cmi5xAPI profile

cmi5 packages launched from a lesson, writing to the academy's own LRS.

LTI 1.3Deep Linking · Grades

An LTI 1.3 tool: academy programmes inside Moodle, grades passed back. Tested with Moodle.

MCP — FOR AI AGENTS

An AI agent can use TKAWEN OS directly

TKAWEN OS ships its own Model Context Protocol server. An assistant connected to it can search the courses of every live academy at once, open a course card, verify a certificate by its code and name the issuer, check whether a name is free for a new academy, and fetch the LTI 1.3 settings to paste into Moodle — all read-only, from the same public endpoints a visitor uses.

search_courses

One query across every academy, Arabic-aware, filtered by level, language or certificate.

verify_certificate

Asks every academy register; answers valid or not, with the issuer, holder, course and date.

lti_setup

The academy's LTI 1.3 registration — login, launch, deep-linking and JWKS URLs — ready for Moodle.

07 — PERMISSIONS

Permissions are enforced on the server

The interface hides what is not yours, and the server refuses it — instructors are scoped to their own courses by the same access policies that protect the data.

CapabilityOwnerInstructorLearner
Manage the academy, branding and instructors●——
Publish courses and review payments●——
Build own courses: modules, lessons, quizzes●●—
See learners and grades of own courses●● own only—
Learn, take quizzes, receive the certificate——●
08 — SECURITY & OPERATIONS

Operations and security

Full isolation

Database, storage, cache and queue per academy.

Encrypted keys

An Ed25519 key per academy; the private key encrypted at rest.

Daily backups

Every database daily: 14 days on the server, 90 days in off-site storage.

Encrypted transport

TLS on every academy subdomain; provisioning that rolls back on failure.

09 — IN PROGRESS

In progress

A technical reference states what is not finished yet, so decisions rest on what exists.

Custom domainsEvery academy runs on academy-name.tkawen.com today; mapping an institution's own domain is not built yet.
Offline learningProgress pings are queued locally and sent when the network returns; playing lessons offline is not built.
Auto-renewing billingSubscriptions are fixed-period passes today.
AlgeriaCertify and LIQAA bridgesWritten, not switched on: certificates are signed with the academy key, and a live session is a link to an external meeting.

Seeing it run beats any explanation

The demo academy is open with owner, instructor and learner accounts, and resets to its initial state every night.