The problem
A printed credential makes a claim that was true on the day it was printed. A degree certificate, a training card, an inspection report, a licence, a carbon certificate: each asserts something at a moment, then goes out into the world and keeps asserting it whatever happens afterwards.
Two failures follow. Forgery is the obvious one, and it is now trivial, because a document is a design file and a printer. The subtler one is worse: the genuine document that should no longer be relied on. The qualification that was revoked. The certification that lapsed. The inspection superseded by a later failure. Nothing about the paper changes, so nothing about the claim changes.
Verification usually means ringing the issuer. Most people do not, which is what makes both failures work.
How VCode is deployed
Each document is issued with its own VCode, printed on the document itself. The code identifies that individual instrument, not the document type, so two copies of the same certificate issued to two people are two different codes.
The issuer keeps the authoritative record: what this document says, who it was issued to, when it expires, and whether it still stands. Rules control who may verify it and what they are shown.
What happens when it is scanned
A verifier scans the code on the document in front of them. The platform confirms whether this specific document is authentic, current, and what it actually says according to the issuer today rather than on the day of printing.
The revocation case is the one that sells this. An issuer withdraws a certificate. The holder still has the printed document, unchanged, in their hand. From that moment the same piece of paper reports that it has been revoked. No reissue, no recall, no ringing anybody.
Every verification is recorded, so an issuer can see that a credential was checked, when, and how often, which is itself useful in regulated settings.
Why a QR code or NFC alone is not enough
A QR code printed on a certificate points at a verification page. That is a real improvement on nothing, and plenty of issuers do it. Its limits: the code can be copied onto a forged document along with everything else, so the forgery verifies as happily as the original unless the landing page compares what it shows against the paper. Anyone can generate a convincing lookalike code pointing at a convincing lookalike page. And the issuer sees a page view, not a verification of a specific instrument.
NFC is impractical for most paper documents on cost and durability grounds, though it is used for passports and ID cards, where the document is a manufactured object and the security budget matches.
VCode’s difference is that the code cannot be manufactured outside the platform, so a forged document cannot carry a working one, and the answer reflects the issuer’s position at the moment of the check rather than at the moment of printing.
What it changes commercially
- Revocation becomes real. Withdrawing a credential actually withdraws it, in the field, on documents already issued.
- Verification stops costing you staff time. Employers and regulators check the document instead of your telephone.
- Forgery loses its route. The code on a fake cannot resolve, so the fake fails a check the verifier can perform in seconds.
- You can see reliance. Who is checking which credentials, and how often.
Integration
Codes are minted per document through the platform API at the point of issue and placed into your existing document template. Verification runs through your own portal or application using the SDK, so a regulator or employer verifies inside your service. Revocation is a call to the API. Scan history provides the audit trail. See the developer documentation.
Issuing credentials people rely on?
Tell us what you issue and what happens today when one has to be withdrawn.
