Technology

The Five Fields a Contractor Credential Check Has to Return — and the One Nobody Ships

The Five Fields a Contractor Credential Check Has to Return — and the One Nobody Ships

The Five Fields a Contractor Credential Check Has to Return — and the One Nobody Ships

A lookup on a public contractor license register returns a small, fixed set of things: a registered company name, a registration number, a class or grade of work, and a word describing standing. It is rendered as a page, for a person, one company at a time. Two things a buyer is actually deciding on are not in that field list. When was this last true. Has it since been withdrawn. Both questions have real answers inside the issuing body’s own records. The register simply has no field built to hold either one.

Authoritative, Public, and Unreadable at the Speed of a Decision

The registers are not deficient as registers. They are official, complete, and free to search — published as human-facing lookup pages, one query, one company, one screen. A decision at consumer speed needs a response instead: a structured answer a system can request, compare, and act on without a person reading a page. Authority and readability turned out to be separate properties.

Angi puts the cost of hiring an unlicensed contractor at $300 to $500 a day, or 10 to 20 percent of the project, with average costs near $4,000 — a consumer brand’s estimate, not an industry finding. CSLB, California’s licensing board, sets administrative penalties between $200 and $15,000, or 20 percent of the contract price or $5,000 — a regulator’s figure, not a market estimate.

Both figures describe the cost of an answer that arrived wrong or late. Neither describes anything the register charges for — the information was public and free. That asymmetry is why a verification market exists.

What the Verification Market Agrees On (and the Word Missing From All of It)

Four vendors describe what their responses return, and the field lists converge. statelicense.io verifies contractor licenses across five states through one normalized API — normalization across registers is what it sells. contractorverify.org returns real-time status, expiration, bond information, and disciplinary actions. checklicensed.com returns status, bond information, and workers’ compensation, priced per lookup. Cobalt Intelligence checks license status, expiration dates, and disciplinary actions across state boards. Across the nine vendors surveyed, the same four fields recur: identity, status, an expiration date, and a bond or disciplinary history.

checklicensed.com discloses $0.25 per lookup; tradesapi.com discloses 50 free lookups, then $99 for 400. The answer costs cents; the wrong answer, on the figures above, costs thousands. That gap is what this market gets paid to close.

In their own public descriptions of what a response contains, none of these vendors names revocation as a field of its own. Status and disciplinary actions carry the weight instead, and a status flag is a point-in-time reading, not a change event. It is an omission common to every description in the set, not a claim about any one product.

The Five Fields a Credential Response Has to Carry

A machine-checkable credential response needs five fields a register would have to emit.

1. Identity That Resolves to a Registered Entity

The field: a registration number that resolves to one legal entity, not a trading name someone typed by hand. The test: Cobalt Intelligence’s own help documentation recommends capturing license numbers in a structured field to standardize inputs — necessary only because the input arrives unstructured today. The identity key exists; it is a string somebody transcribes.

2. Grade and Scope, Not Just a Status Word

The field: what class of work the credential authorizes, and up to what value. The test: this field is exposed. A scraper of California’s licensing board returns classifications, bonds, workers’ compensation, and disciplinary disclosures, but the vocabulary is per-register — which is why statelicense.io sells normalization across five states. Exposed, and not comparable.

3. A Validity Window With an As-Of Date

The field: not only an expiration date, but the date the answer itself was true. The test: expiration dates are exposed across the vendor set surveyed; an as-of timestamp on the response appears in none of their descriptions. Freshness is carried entirely by whoever asked last, and by when.

In practice, a contractor-matching platform in Tshwane presents property owners with independent contractors after checking experience, CIDB and NHBRC compliance, at no cost to the owner. The check is made before a contractor is presented; the register emits nothing afterward, so nothing downstream can observe a later lapse: one instance of the gap.

4. Revocation State as a Field of Its Own

The field: whether a credential has been withdrawn before its expiration date, for cause — different from whether it has expired. The test: it fails today. The field is named in none of the descriptions surveyed, and its two proxies — a status word, a disciplinary history — are conditions, not change events a system can subscribe to.

5. Provenance: Which Register Answered, and How

The field: which authority the answer came from, and whether it arrived native or scraped. The test: on one result set, California’s board publishes a human lookup, a third party sells a scraper of that board, and a normalization layer resells both shapes through one interface. None of the response formats says which one produced the answer.

The Same Distinction, Already Standard in Another Registry

Certificate authorities have separated two questions for decades: is this certificate inside its validity period, and has it been revoked since it was issued? The second is published separately and by name — certificate revocation lists, and the online status protocol that replaced polling them. The specifications defining both are published by the IETF.

The transferable part is a data-publishing pattern, not security infrastructure: revocation only works when the issuer publishes the withdrawal as an event, because nothing downstream can infer it from an expiration date. Applied to a construction register, that locates the burden on the body that grades and enrolls contractors, not on the aggregator reselling a lookup of it.

The certificate world has an enforcer construction does not: a browser that refuses the connection. A register publishing revocation events would still depend on whoever bothered to ask. Business-verification vendors, checked for the same field, do not name revocation either — the precedent is the certificate world’s.

What Changes When a Register Publishes Events Instead of Pages

The aggregators cannot add a field their source does not emit. They can normalize, cache, and resell — that is the ceiling on what a downstream layer can do. The change has to start at the register, and it is a publishing decision before it is a technology one.

A credential response carrying all five fields would make a machine-speed decision defensible on the same evidence a regulator already holds — no new authority created, no new register built, the same facts emitted in a shape a system can consume.

Nine vendors already agree on four fields. Revocation, published as its own event rather than inferred from a status word, is the field none of them names at all.

Frequently Asked Questions

What Is API-Based Verification?

API-based verification checks a credential by requesting a structured response from a system, rather than having a person read a lookup page. That distinction decides what can be checked at scale: a page opens one company at a time, while a structured response can be requested, compared, and logged automatically.

Isn’t an Active Status the Same Thing as Not Revoked?

No. A status flag reads a condition at the moment it is checked; revocation is an event with a date. A credential can show active status and have been withdrawn an hour earlier, because nothing has emitted the change yet. An answer can be stale without being wrong.

Why Can’t a Verification Vendor Simply Add a Revocation Field?

Because a downstream layer can only surface what its source emits, and normalizing several registers into one interface does not create data that was never published. The field can originate only at the register, the body that issued the credential and can record when it withdraws one.

Does a Scraped Answer Count as Verification?

A scraped copy of an official board’s page carries the same facts as the source it copies, but none of the guarantees about when they were read. The response format does not distinguish a native answer from a scraped one, so a buyer cannot tell which register stands behind it.

 

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This