QRCertificates
GuideVerificationInstitutions

Verifiable certificates: a complete guide for institutions and employers

A seal and pen beside a checklist, representing confirming certificate legitimacy
Key takeaway

One long read covering the whole problem: why PDFs prove nothing, what makes a credential checkable, and how to get there without a large project.

This is the long version. If you issue certificates, letters or marksheets and you have ever been asked "is this genuine?", everything below is the ground you need to cover. It is written to be read once, end to end, and then used as a reference.

1. The problem, stated plainly

A PDF certificate proves nothing. Anyone can open one in an editor, change a name, a grade or a date, and re-save it. The letterhead copies. The scanned signature copies. The seal copies.

What makes a credential meaningful is not the document. It is the ability to confirm the document against the issuer. Without that, a certificate is a picture of a claim.

2. What actually happens to an unverifiable certificate

It is not rejected. It is quietly discounted.

A recruiter with forty applications and an afternoon has three options when an unfamiliar credential appears: spend ten minutes trying to confirm it, accept it and carry the risk, or move on. Under time pressure the third wins, and nobody tells the holder or the issuer. That silence is why the problem persists.

3. What "verifiable" actually requires

Four properties. Everything else is decoration.

  • A unique reference per document. Not the roll number or employee ID, those identify a person. This identifies this document, because one person may hold several.
  • A public verification page. Openable with no account and no app, from outside your network.
  • A signature over the record. Not a scanned image of handwriting, and not merely a signature on the file: a cryptographic signature over the actual data, so an altered copy fails rather than passes.
  • A revocation path. Documents get issued in error. You need a way to mark one invalid without pretending it never existed.

4. Why signing the data matters more than signing the PDF

This is the distinction that separates real verification from theatre.

A verification code that only confirms "a record exists with this code" will validate a forged document carrying a genuine code. Someone edits the name, keeps the code, and the lookup says yes.

Signing the canonical record, recipient, course, dates, and for a marksheet every subject row, means the verification page can display what the issuer actually asserted. A mismatch becomes visible instead of hidden.

5. Things that look like security and are not

  • Holograms and watermarks. Reassuring, and stop nobody with a printer.
  • "Contact us to verify". The contact details are printed on the document, so a forgery carries forged contact details.
  • Verification behind a login. If a recruiter must register to check a certificate, they will not check the certificate.
  • Blockchain, by itself. Publishing a hash to a ledger proves a record existed at a time. It does not establish who issued it or that the holder's copy matches. Public-key signatures do the work; the ledger is optional.

6. What belongs on the document

Identity: name as it appears in official records, and a second identifier, date of birth or enrolment number, so a verifier can disambiguate common names.

Substance: what was completed, over what period, and what was assessed. "Certificate of Completion" alone tells a reader nothing.

Provenance: the issuing body, the authority, and the date of issue.

Verification: a unique reference, and the verification URL both as text and as a QR code. Put them in the lower margin, not an extreme corner, so photocopying does not crop them. Print the URL in text as well, scanners fail and faxed copies degrade.

For marksheets, add the grading scale. A 7.4 is uninterpretable without knowing the maximum, and its absence is the single most common cause of follow-up enquiries from abroad.

7. What to leave off

Personal contact details. Internal codes with no external meaning. Salary or reason for leaving on an experience letter. Anything you cannot commit to keeping accurate, such as a department head's name that changes annually.

8. Documents change: plan for it

Revaluation, corrections and re-issues are normal. Decide the policy before the first case, not during it.

Supersede rather than overwrite: issue a new document with its own reference, mark the previous one superseded, and keep the old reference resolvable so it points at the current version. Never silently mutate a record, an old identifier that suddenly returns different data destroys the audit trail and makes a genuine holder look like a forger.

9. For Indian institutions: where the national systems stop

Degrees, diplomas and semester marksheets belong in the National Academic Depository, surfaced to students through DigiLocker, with APAAR tying a learner to their Academic Bank of Credits. Publish them there.

That scope is deliberately narrow, and it excludes most of what an office signs: workshop and FDP certificates, internship and training letters, bonafide and conduct certificates, event and hackathon awards, and anything issued by a centre or cell under your name.

Those are the documents that generate most verification email: higher volume, held by earlier-career people, and least recognisable to a recruiter. They need their own verification. The two approaches are complementary, not competing.

10. For employers: the letters you issue

Attention goes to detecting fake letters arriving. The letters you send out are the half you control, and every one issued on plain letterhead becomes a template someone can edit.

Give each a unique reference and a verification page showing name, designation, employment dates and status, and nothing more. Salary and reason for leaving are between you and the former employee. The result: forged copies of your letterhead stop verifying, and your HR team stops fielding calls about people who left years ago.

11. Rolling it out without a large project

  1. List every document type you issue in a year. Not just the formal awards.
  2. For each, estimate annual volume and how many verification queries it attracts.
  3. Start with the highest product of those two numbers. It is rarely the document anyone was worrying about: usually internship, workshop or bonafide certificates.
  4. Do one document type, one cohort, end to end.
  5. Put the verification URL on the document itself so the next request answers itself.
  6. Measure inbound verification email before and after. That comparison is the case for expanding.

12. How to test whether it actually works

Take one real certificate you have issued. On a phone, using mobile data, with no VPN, in a private browsing window, scan the QR code.

You should reach a page that names the holder, names what they completed, and states clearly whether the document is valid: without asking you to log in.

If you reach a login screen, a timeout, or a page that merely echoes back a code, you have found the gap before an employer did. That single test is worth more than any vendor's feature list.

A short closing

None of this requires accreditation, a large budget or a blockchain. It requires the document to answer the only question anyone will ever ask of it: is this real, and who says so?

Institutions that get there stop treating verification as an administrative burden and start treating it as something the document does by itself.

FAQ

Frequently asked

What makes a certificate verifiable?

Four things: a unique reference for that document, a public verification page that opens without an account, a cryptographic signature over the record so an altered copy fails, and a revocation path for documents issued in error.

Why isn't a verification code enough on its own?

A code that only confirms a record exists will validate a forged document carrying a genuine code. Signing the canonical record, recipient, course, dates, subject rows, is what makes tampering detectable rather than hidden.

Do holograms or watermarks help?

Not meaningfully. They look reassuring and stop nobody with a printer. Independent checkability by a third party is what establishes authenticity.

Is blockchain required for verifiable certificates?

No. Publishing a hash to a ledger proves a record existed at a point in time; it does not establish who issued it or that the holder's copy matches. Public-key signatures do that work, and the ledger is optional.

Where should an institution start?

With the document type whose annual volume multiplied by its verification queries is highest: usually internship, workshop or bonafide certificates, not degrees. Do one type, one cohort, end to end.

How do we handle corrected or reissued documents?

Supersede rather than overwrite. Issue a new document with its own reference, mark the previous one superseded, and keep the old reference resolvable so it points at the current version.

Issue your first credential in minutes

Start free, no credit card. Design a certificate, issue a verifiable copy, and watch it verify on a public page. Scale to thousands when you are ready.