TKAWEN OS
An operating system for training institutions. Each institution gets a complete academy on its own address your-academy.tkawen.com, running on a database of its own, issuing certificates cryptographically signed with its own key — from the first lesson to the verification page.
Five layers, one request path
Every request enters through the academy's subdomain. The tenant is resolved from that subdomain before anything else, and from then on the request only touches that academy's data.
nginx · *.tkawen.comSvelteKit · /manageLaravel 13tkawen_<slug>Ed25519A complete academy in one command — or nothing
Provisioning is not copying a template. One command builds the tenant, its database and tables, the owner account, roles, theme, certificate template and signing key. If any step fails — a database that cannot be created, a migration that does not finish — everything is rolled back: no half-built academy, no account nobody asked for.
$ php artisan tenant:provision acme \ --name="Acme Academy" --owner-email=owner@acme.dz ✓ tenant acme.tkawen.com ✓ database tkawen_acme (created + migrated) ✓ owner owner@acme.dz · tenant admin ✓ roles owner · instructor · student ✓ theme logo · colours · locale ar ✓ certificate template ready ✓ signing key Ed25519 · stored encrypted Academy 'Acme Academy' provisioned. ↺ on failure: tenant, database and new owner rolled back
- database
tkawen_acme - storage
storage/acme - queue
queue:acme - signing key
ed25519:acme
- database
tkawen_nour - storage
storage/nour - queue
queue:nour - signing key
ed25519:nour
- database
tkawen_atlas - storage
storage/atlas - queue
queue:atlas - signing key
ed25519:atlas
NO SHARED DATABASE · NO SHARED STORAGE · NO SHARED QUEUE
Three interfaces, each role with its own tools
The owner's panel runs the whole academy, instructors see only their own courses, and learners use the app on desktop and phone. Real screenshots of the demo academy (Arabic interface).



Curriculum builder
Modules, lessons and quizzes, with a sequential lock chosen by the instructor.

Learning room
Lesson after lesson; progress recorded on the server.

Enrolments & progress
Each learner's progress and status, with an early warning after 14 days of inactivity.
The learning engine
Nine lesson types, seven question types, and a sequential lock enforced by the server, not the interface — nobody skips a lesson by editing a URL.
Video
Audio
Text
Quiz
Assignment
Live session
SCORM
xAPI · cmi5
Sequential lock
open · prev · prev_pass
7 question types
Single choice, multiple choice, true/false, free text, matching, fill-the-gap, keywords.
Pass mark & attempts
Each quiz has a pass mark and an attempt limit (3 by default), with a gradebook for the instructor.
Early warning
A learner inactive for 14 days surfaces to the instructor before they drop out.
A certificate that cannot be forged — by mathematics, not by stamp
Nobody types a certificate by hand. It is issued automatically at 100% completion with the final quiz and all assignments passed, then signed with the academy's own Ed25519 key. Changing a single character invalidates the signature, and verification reads the registry — not an image or a PDF.
{
"status": "valid",
"code": "TK-LJA74G2Z",
"holder": "Demo Student",
"programme": "Git & GitHub",
"issuer": "Demo Academy",
"credential_id": "crd_01m2ya21azztz6bmx6esgje3ns",
"signature": "Ed25519 ✓"
}Real screenshot of the demo academy's verification page in English (holder and course names are the demo's Arabic data). 11 certificate designs plus a free designer, in Arabic and English.
Speaks the language of the world's learning systems
Content authored with standard tools runs as is, learning records are written to an open standard, and the academy opens inside Moodle and sends grades back.
Runs SCORM packages and records progress and score.
xAPI statements stored in a Learning Record Store per academy.
cmi5 packages launched from a lesson, writing to the academy's own LRS.
An LTI 1.3 tool: academy programmes inside Moodle, grades passed back. Tested with Moodle.
An AI agent can use TKAWEN OS directly
TKAWEN OS ships its own Model Context Protocol server. An assistant connected to it can search the courses of every live academy at once, open a course card, verify a certificate by its code and name the issuer, check whether a name is free for a new academy, and fetch the LTI 1.3 settings to paste into Moodle — all read-only, from the same public endpoints a visitor uses.
{ "jsonrpc": "2.0", "id": 1, "method": "tools/call",
"params": { "name": "search_courses",
"arguments": { "q": "python", "certificate": true } } }
tools: overview · academies · search_courses · course
verify_certificate · check_subdomain · lti_setup
gateway: https://mcp.tkawen.com (as os__*)
search_courses
One query across every academy, Arabic-aware, filtered by level, language or certificate.
verify_certificate
Asks every academy register; answers valid or not, with the issuer, holder, course and date.
lti_setup
The academy's LTI 1.3 registration — login, launch, deep-linking and JWKS URLs — ready for Moodle.
Permissions are enforced on the server
The interface hides what is not yours, and the server refuses it — instructors are scoped to their own courses by the same access policies that protect the data.
| Capability | Owner | Instructor | Learner |
|---|---|---|---|
| Manage the academy, branding and instructors | ● | — | — |
| Publish courses and review payments | ● | — | — |
| Build own courses: modules, lessons, quizzes | ● | ● | — |
| See learners and grades of own courses | ● | ● own only | — |
| Learn, take quizzes, receive the certificate | — | — | ● |
Operations and security
Full isolation
Database, storage, cache and queue per academy.
Encrypted keys
An Ed25519 key per academy; the private key encrypted at rest.
Daily backups
Every database daily: 14 days on the server, 90 days in off-site storage.
Encrypted transport
TLS on every academy subdomain; provisioning that rolls back on failure.
In progress
A technical reference states what is not finished yet, so decisions rest on what exists.
academy-name.tkawen.com today; mapping an institution's own domain is not built yet.Seeing it run beats any explanation
The demo academy is open with owner, instructor and learner accounts, and resets to its initial state every night.
