← All documentation

Verification and revocation

Every certificate has a permanent public verification URL and QR code. Recipient email is never displayed publicly.

Statuses

Downloads

PNG and PDF endpoints are stable render-on-demand URLs while a certificate is valid. A completed canonical render records an immutable SHA-256 fingerprint. Revoked or expired PNG responses receive a visible status overlay at delivery time and are never cached; their PDF and explicit download requests are blocked. The verification page remains the authoritative status record.

Revoke

Dashboard owners or API keys with certificates:revoke can revoke a certificate. Revocation is idempotent and refreshes the public cache. Keep the reason concise and free of sensitive personal data.

Reinstate

Reinstatement removes a valid revocation when policy permits. It does not change the certificate ID, issue date, template version, or verification URL.