How to add a QR verification code to certificates
A PDF certificate is easy to edit, so anyone can change the name on one. A QR code that opens a page on your issuer's record lets an employer confirm a certificate in seconds. Here's how it works and how to set it up for a whole batch.
How QR verification works
- Each certificate gets a unique, random ID, e.g.
CS-7K3M-9QX2-H4TB. - The issuer stores a small record for that ID: who it was issued to, for what, by whom and when.
- The QR code on the certificate encodes a web address containing the ID, e.g.
https://certsheet.com/v/CS-7K3M-9QX2-H4TB. - Whoever scans it sees a page that says “Valid certificate” with the stored details, or “not found” or “revoked”.
The check is simply whether the details on the paper match the details on the page. If someone edits the name on their PDF, the verification page still shows the original name.
A worked example
A security training company in Kingston issues 120 “Fire Warden” certificates after a site course. Employers often ask candidates for proof. The company:
- Uploads the class list (Name, Course, Date) to CertSheet and picks the Heritage template.
- Turns on Publish for online verification and enters the issuer name “Kingston Safety Training Ltd”.
- Places the QR code in the bottom-right corner at 62 pt (about 22 mm) with the ID printed underneath.
- Generates the batch. Each certificate's code now opens a page like this:
Recipient: Tamara Henry
Title: Fire Warden
Issued by: Kingston Safety Training Ltd
Date: 3 October 2026
Certificate ID:
CS-Q4ZB-7MRT-2KDX
Six months later, one certificate turns out to have been issued in error. The company revokes the batch in the app, re-issues the rest, and the old codes now show “Certificate revoked”.
What to publish, and what not to
A verification page is public to anyone holding the code, so publish the minimum needed to confirm the certificate:
- Publish: recipient name, certificate title, issuer, date, certificate ID.
- Don't publish: email addresses, phone numbers, ID or passport numbers, dates of birth, grades or anything sensitive.
CertSheet stores exactly those five details and nothing else from your spreadsheet. Its verification pages tell search engines not to index them, and its IDs are random, so pages can't be found by guessing sequential numbers.
Placing the code so it scans
| Guideline | Why |
|---|---|
| At least 2 cm (about 57 pt) wide when printed | Smaller codes fail on older phone cameras |
| Dark code on a white square with a clear margin | Scanners need contrast and a quiet zone around the code; CertSheet adds the white margin automatically |
| Keep the address short | Short addresses make simpler codes that scan from further away. Avoid long tracking links |
| Print the ID in text under the code | People can type it in if the code is damaged or a scan isn't possible |
| Put it in a corner, away from signatures | Keeps the design clean and stops the code overlapping ink stamps |
| Test-scan one printed copy before printing all | Catches size and contrast problems before they're multiplied |
Three ways to set it up
- A spreadsheet plus a QR generator: make an ID column, a link for each row, and generate codes one by one. This works for 10 certificates but is slow and error-prone for 200, and you also need to host the verification pages.
- A learning management system: many have verification built in, but only for courses run inside that system.
- A batch tool with hosted verification: upload the list once; IDs, QR codes and pages are created together. In CertSheet, every certificate gets an ID and QR code on every plan. Online verification pages are included with Pro and the Event Pass.
Revoking certificates
Verification is only trustworthy if mistakes can be withdrawn. In CertSheet, your published batches are listed under online verification with a Revoke button. Revoked certificates show a clear “Certificate revoked” page rather than disappearing, so whoever checks it learns it's no longer valid.
For the rest of the process, see how to make certificates from a spreadsheet.