Verifiable certificate generator

Verifiable certificates: what the QR code should prove

Connect each managed credential to a privacy-conscious verification record instead of placing unverifiable decoration on the certificate.

Reviewed 2026-08-19.Reviewed by

A verification QR code is useful only when it resolves to an authoritative record with a clear current status. FotoFit managed credentials can connect a generated certificate to a verification page; temporary renders do not create that durable record.

What a verification page should answer

  • Was this credential issued by a recognised workspace?
  • Which recipient or public identifier does it belong to?
  • What was issued and when?
  • Is the record currently valid, revoked or unavailable?
  • Is the page making only claims the stored record can support?

Managed records are the durable layer

The image or PDF is the presentation. The managed record is the history that supports verification, later correction and regeneration. This is why temporary output cannot provide the same lifecycle.

Protect recipient privacy

Expose only the information necessary for verification. Avoid putting private spreadsheet fields, email addresses or source-image URLs into public pages or QR payloads.

Verification is not the same as accreditation

FotoFit can show what a workspace issued and the current record status. It does not independently accredit an institution, validate the underlying course or guarantee that every external organisation will accept the credential.

Common questions

Can temporary certificates be verified later?

Not as managed FotoFit credentials. Run a managed job when durable verification is required.

Can a corrected credential keep its history?

Managed records are intended for controlled edits and regeneration rather than silently replacing an unrelated file.

Related resources