Skip to content

Guides

How do you verify that a certificate is genuine? By code, QR code and file

How to check that a university certificate or digital badge is genuine, unmodified and still valid using its short code, QR code or file.

Last updated: Author: EXERT5 min read

Summary

  • Verification confirms that a document is genuine, unmodified and still valid; the signature, the issuer and the revocation status are checked together.
  • DijiUni badges are verified at dijiuni.com/en/verify by short code, verification link, QR code or file (PNG, SVG, PDF, JSON); no account is needed.
  • The result is not just valid or invalid: revoked, suspended, expired, tampered and unknown issuer are shown separately.
  • Verification proves the document is genuine; whether the person presenting it is the holder may need a separate check.

What does verification prove?

To verify a document is to answer three questions:

  1. Is it genuine? Was it issued by the institution named on it?
  2. Has it been changed? Were the name, date, programme or credit changed after issue?
  3. Is it still valid? Has the institution revoked or suspended it, or has it expired?

For printed or PDF documents these answers usually require a letter or phone call to the issuing institution. For a signed digital badge all three are answered online in seconds.

Method 1: by short code or verification link

DijiUni badges and certificate PDFs carry a short code and a verification link.

  1. Open dijiuni.com/en/verify by typing the address yourself.
  2. Paste the short code or the full verification link into the field.
  3. Select Verify.

Tip: typing the verification address yourself, rather than clicking a link inside a PDF you were sent, removes the risk of being taken to a look-alike fake verification page.

Method 2: by QR code

The QR code on the document opens the verification page with the document's code.

  1. Scan the QR code with a smartphone camera, or use Scan QR on the verification page.
  2. Check that the address that opens is on the dijiuni.com domain.
  3. Compare the status seal and details on the result screen with the document you hold.

Method 3: by uploading the file

Open Badges 3.0 badges can carry the signed data inside the file. If you received a badge image or certificate PDF by email:

  1. Choose Upload file on the verification page.
  2. Upload the PNG, SVG, PDF or JSON file (up to 10 MB).
  3. The system reads the embedded signature and verifies it.

If even one character has been changed since issue, the signature no longer matches and the result shows Tampered.

How to read the result

ResultMeaningWhat to do
ValidSignature, issuer and status list verifiedCompare the details with the document presented
RevokedThe institution revoked the documentIt no longer proves a qualification
SuspendedThe institution suspended it temporarilyContact the institution
ExpiredThe validity period has endedAsk for a current document
TamperedThe content does not match the signatureDo not accept the document
Unknown issuerThe signature can be read but the issuer is not on the trust listConfirm the institution separately

The checks section below the result shows what the system checked in order: structure, issuer, signature, time, status list and, where relevant, YÖK approval. Each step shows a pass or fail mark with a short explanation. Technical teams can view the signature header and raw data under Technical details.

Is the person presenting it really the holder?

Verification proves the document is genuine; it does not by itself prove that the person presenting it is the holder. On some badges the holder's name is hidden on the verification page because of privacy settings. In that case an identity check field appears: entering the person's date of birth or the last four digits of their Turkish ID number shows the name temporarily if it matches. In hiring and similar processes this check is best combined with an identity document.

Relationship with e-Devlet verification

The Document Verification (opens in a new tab) service of the e-Devlet Gateway checks documents by barcode number. For SEM certificates, verification on e-Devlet is planned for YÖK-approved programmes from 1 October 2026 (details). e-Devlet does not store documents; it forwards the query to the issuing institution's service. Where an institution has enabled that service, the DijiUni result shows a "verifiable on e-Devlet" mark and the same certificate number can be queried there.

Checklist for employers

  1. Open the verification address by typing it, not from the link on the document.
  2. Check that the result is Valid and that the issuer is the institution you expect.
  3. Compare programme name, date and credits (ECTS) with the document presented.
  4. If the name is hidden, use the identity check or match it with an identity document.
  5. Record the result with date and time; the same document can be verified again later.
  6. If the result is Tampered, Revoked or Unknown issuer, contact the named institution through its official channels.

Why a fake cannot be spotted by eye, and what institutions can do, is covered in The fake certificate problem.

For organisations that verify in bulk

For organisations that check many documents regularly (HR departments, recognition committees) DijiUni offers a key-based verification API that runs the same checks as the verification page and returns a machine-readable result. Because badges carry a did:web identity, other compatible verifier software can also check the signature against the institution's public key without contacting DijiUni.

The verification portal is free and needs no account: Verify a badge.

Frequently asked questions

Do I need an account to verify?
No. The verification page is public and free; a short code, link, QR code or file is enough.
What does "Tampered" mean?
The content does not match the institution's signature. The file may have been changed after issue; the document should not be accepted.
Why does a revoked document still exist?
Distributed copies are not deleted, but the revocation is published in the institution's status list, so the document shows as revoked at the next verification.
Can I verify badges from other platforms?
Open Badges 3.0 compatible badges can be uploaded as files and their signatures checked. If the issuer is not on the trust list, the result shows "Unknown issuer" and the institution should be confirmed separately.

Sources

  1. 1EdTech — Open Badges 3.0 Implementation Guide (opens in a new tab)
  2. W3C — Verifiable Credentials Data Model 2.0 (opens in a new tab)
  3. W3C — Bitstring Status List v1.0 (opens in a new tab)
  4. W3C CCG — did:web Method Specification (opens in a new tab)
  5. e-Devlet Gateway — Document Verification (opens in a new tab)
  6. Anadolu Agency — YÖK to strengthen quality assurance in lifelong learning (Turkish) (opens in a new tab)

Links were accessible as of September 2026. Details that are not public are not claimed in the article.

Verify a document now

By short code, QR code or file; no account needed.