Certification and Trust Badges
Every published version gets a trust badge. The badge is how a buyer tells "trust me" from "the platform checked it".
- Execution certification is not enabled. Every listing shows the Verified badge. The Certified badge appears when the platform turns certification on.
The three badges
| Badge | What it means |
|---|---|
| Community | Published. No checks have passed yet. |
| Verified | The version passed the platform's automated static checks. |
| Certified | The platform ran the exact published version in an isolated workspace and verified the proof. Available for bots, skills and workflows. Teams stay Verified until their activation harness is part of certification. |
Today in production every listing shows Verified at most. Certified becomes available when execution certification is turned on.
What a certification run does
- You publish a version. The static checks run and a pass earns Verified.
- In the Seller Hub, open the Certification section and choose Run certification on the listing.
- Bots and skills deploy as probe agents in an isolated certification workspace. The probe runs once and must produce non-empty output.
- Workflows import into the same workspace and run on the hosted workflow runtime in dry-run mode. Side-effecting steps are mocked: messaging, payments, webhooks and similar.
- The workspace is isolated from customer data. Probe and fixture objects are deleted afterward.
- A pass sets the version to Certified and the badge updates everywhere the listing appears. A failure gives a check-by-check report.
A run usually takes under a minute.
The tier follows the latest version
Certification belongs to one version. Publishing a new version resets the badge to what that version has proven. Re-run certification after every update.
Mocked connection steps
A workflow step that needs a buyer's connection, for example a HubSpot action, cannot run for real in the certification workspace. The run mocks it automatically, including the approval and access requirements the import attaches to that step. The report then says it ran with N connection steps mocked and that the real connections were not exercised.
Setup on any other step fails the check Workflow has no setup a dry run cannot skip. Pick a trigger that needs no setup. A schedule trigger works. A webhook trigger asks for an entity type and fails.
Read the report
Each check shows pass or fail:
| Check | What it tells you |
|---|---|
| Published manifest passed static checks | Structure and required fields are valid. |
| Published version and content hash matched | The run used the exact version buyers get. |
| Workflow imported into the certification workspace | The importer accepted it. |
| Workflow has no setup a dry run cannot skip | No unresolved credential, configuration, resource or adapter setup remains. |
| Workflow proof mapped to executable nodes | Your fixture points at nodes that exist. |
| Temporary objects cleaned up | The run left nothing behind. |
A failed run names which step broke: deploy, run or output.
Proof fixtures for workflows
A workflow manifest can declare a bounded proof under spec.certification:
{
"triggerData": { "lead": { "score": 91 } },
"nodeMocks": { "send-draft": { "drafted": true } },
"assertions": [
{
"name": "lead normalized",
"type": "step_status",
"nodeId": "normalize",
"status": "completed"
},
{ "name": "draft produced", "type": "output_non_empty", "nodeId": "send-draft" }
]
}
- Assertion types:
step_status,output_non_empty,output_equals. - Limits: 64 KiB, 64 trigger and mock entries, 32 assertions.
- Unknown fields and executable assertion scripts fail static verification.
nodeMockskeys and assertionnodeIdvalues use the source n8n node IDs. Unknown or non-executable nodes fail before the run starts.- Without a fixture, a completed dry run is the proof.
What certification gives you
- The Certified badge on every surface that shows your listing.
- Sealing. You can only seal a listing whose latest version passed an execution run. See Open and sealed listings.
Academy credentials
The Builder Academy is a separate system. It certifies you, not a listing. Credentials appear on your publisher profile.
| Level | How you earn it |
|---|---|
| 1. Builder Associate | A written exam on the fundamentals. Also granted automatically when you publish your first execution-certified listing. |
| 2. Builder Professional | A written exam built from real situations. |
| 3. Certified Agent Builder | A practical: you build a config for a scenario, the platform runs it and an examiner agent scores it. Needs Builder Professional, at least 2 certified listings and 1 with installs. |
| 4. Certified Operator | Granted by SchemaBounce after a review of managed teams with real retention. |
Listing certification and Academy credentials do not substitute for each other.