Verification and revocation
Every certificate has a permanent public verification URL and QR code. Recipient email is never displayed publicly.
Statuses
- Issued means the certificate is active.
- Expired is computed after the configured expiry instant.
- Revoked means the issuer invalidated the credential.
- Processing means a requested render is still being produced.
Downloads
PNG and PDF endpoints are stable render-on-demand URLs while a certificate is valid. A completed canonical render records an immutable SHA-256 fingerprint. Revoked or expired PNG responses receive a visible status overlay at delivery time and are never cached; their PDF and explicit download requests are blocked. The verification page remains the authoritative status record.
Revoke
Dashboard owners or API keys with certificates:revoke can revoke a certificate. Revocation is idempotent and refreshes the public cache. Keep the reason concise and free of sensitive personal data.
Reinstate
Reinstatement removes a valid revocation when policy permits. It does not change the certificate ID, issue date, template version, or verification URL.