Documentation for every role Use your browser's Print command to save this guide as a PDF.
AuthPlus

Verifier guide

Install the app, scan a code, read the verdict, manage profiles and custody.

Generated from the online documentation on August 30, 2026 · https://authenticity-plus.com/docs/

Contents

  1. Introduction
  2. Core concepts
  3. Getting started
  4. Requirements
  5. Installing the Android app
  6. The verification app
  7. Verifier profiles
  8. Verifying a product
  9. Verdict reference
  10. Verifying assets & documents
  11. Transfers & custody
  12. Scan history
  13. Security
  14. Data & privacy
  15. Notifications
  16. Troubleshooting
  17. Frequently asked questions
  18. Glossary
  19. Support

Introduction

Counterfeiting works because a buyer cannot tell a real item from a convincing copy. AuthPlus closes that gap. A brand registers what it produces, and AuthPlus mints a unique, tamper-proof code for every unit. The code is printed on the product, its label or its certificate. Anyone holding the item can scan that code and receive an immediate, unambiguous answer: Authentic, Authentic with a warning, or Non Authentic.

Every scan is recorded, so the brand sees where and when its products are being checked, and unusual patterns — the same code verified far more often than a single physical item ever could be — surface automatically as warnings.

Protect

Register brands, products, valuables and documents, then issue unique authenticity codes for them.

Verify

Anyone can confirm authenticity in seconds with the mobile app or a web browser — no account required.

Monitor

Follow every verification and transfer on a live audit trail and map, with automatic alerts on abuse.

AuthPlus is delivered as two connected experiences that share one account system:

  • The dashboard (/dash) — a web workspace where brand owners register their catalogue, issue codes, print labels and monitor activity.
  • The verification app (/verify) — a deliberately simple scanning experience, available as an Android app and in any web browser, used in shops, at customs, or by end customers.
  • Names of on-screen elements appear like this: Issue Codes. They match the English interface exactly; in French or Arabic the label is translated but the position is identical.
  • Sequences of navigation are written ProductsNew.
  • Technical values — addresses, file names, settings — appear as code.
  • Numbered procedures always follow the same shape: purpose, prerequisites, the steps, then the expected result.
  • A role badge next to a heading means the feature is limited to that role: Standard user Admin Superadmin Verifier

Three kinds of callout are used:

Core concepts

Everything you protect in AuthPlus follows the same five-level chain. Understanding it makes every screen in the dashboard predictable, because each level is simply a list of the level below it.

LevelWhat it isExample
1. BrandThe name behind your items. Everything you register belongs to a brand.Aurora Watches
2. Subject
Product · Asset · Content
The thing you protect, or a category of them. Its type decides how it is verified.Aurora Chrono 42
3. ItemA concrete unit: a production batch, one individual valuable, or one document entry.Batch AC42-2026-A
4. IssuanceOne act of minting codes for an item. An item can have several issuances over time.10 Public codes, 30 July 2026
5. CodeA single unique authenticity code, printed as text and as a QR code.2H7KLM4GUEXDVM

In the dashboard you walk down this chain by clicking: a brand’s products, a product’s batches, a batch’s issuances, an issuance’s codes. Breadcrumbs at the top of each screen show you where you are and let you climb back up.

A subject’s type is chosen when you create it and cannot be changed afterwards. It determines which section of the dashboard the subject lives in, how codes are issued for it, and what a verifier sees when it is scanned.

ProductsAssetsContents
ForManufactured goods produced in quantityUnique valuables: art, jewellery, collectiblesFiles: certificates, official documents, media
Item meansA production batchOne individual pieceOne document entry
Codes per itemMany — one per physical unitNormally oneOne per uploaded file
Issued byChoosing a quantityChoosing a quantityUploading files — each file becomes one code
Verified byScanning the printed codeScanning the code on the certificateScanning the code, or checking the file itself
Verifier seesBrand, product, batch, dates, scan historyAn ownership certificate with its provenanceA certification record and the document

A code is a short random string, unique across the platform, printed as text and encoded in a QR code. Codes are not sequential and cannot be guessed from one another.

Every code belongs to a code type, chosen at issuance. Code types are configured centrally for the whole platform and typically follow the distribution chain:

Code typeIntended forTypical placement
PublicEnd customers. The default.Visible on the product or its packaging
ResellerDistributors and retail partnersOn the carton or delivery documents
ControlInternal inspection and enforcementHidden or restricted placement

A verifier is the identity under which a scan is recorded — a shop, an employee, an inspector, or simply an anonymous consumer device. Verifiers are not dashboard user accounts; they exist so that an item’s history is meaningful, and so that custody can be tracked as goods move.

Each verifier belongs to a verifier type, which decides how it behaves:

  • Public — created automatically on first launch of the app. No credentials, no setup. This is what an ordinary customer uses without ever noticing.
  • Reseller — for trade partners; also self-provisioning, but tied to reseller codes.
  • Control — restricted inspection accounts. These are created by the platform administrator and handed out with a username and password (see Control verifiers).

Verifier types can also require the device’s location before a scan is accepted, restrict a verifier to codes created by a particular owner, or fill in the verifier’s profile automatically from the device.

Every scan — successful or not — creates an operation: a permanent line in the audit trail recording what was scanned, by which verifier, when, from where, and with what result. Operations are what feed the dashboard’s statistics, the map, and the warning system.

The verdict falls into one of three classes:

VerdictMeaningWhat to do
AuthenticThe code exists, is active, and nothing about the scan is unusual.Proceed with confidence.
Authentic, with a warningThe code is genuine, but the circumstances deserve attention — most often because it has been verified more times than a single item plausibly would be.Treat with care; the item may be genuine while its code has been copied.
Non AuthenticThe code does not exist, or it has been blocked or archived.Do not trust the item. Report it to the brand.

The exhaustive list of outcomes, with the exact message shown for each, is in §12 Verdict reference.

AuthPlus is an evidence system, so records are not destroyed. Instead of deleting a brand, product, item, issuance, code or verifier, you archive it. An archived record stays visible (behind the Archived filter), keeps its history, and can be restored.

Archiving has one immediate, deliberate consequence:

Use it deliberately: archiving a brand silently disables every code beneath it. When you only need to stop one batch, archive that issuance rather than anything higher up the chain.

Getting started

  1. Install AuthPlus from Google Play, or open /verify in a browser.
  2. Open it. A verifier profile is created for you automatically — the home screen shows “Verifying as …”. Nothing to configure.
  3. If a brand gave you credentials (a Control profile, say), add them: VerifiersAdd → choose the type → username and password → Save. Tap the circle on a card to switch profile.

Verification app home screen

Home screen.

Verifier list with the active profile checked

The active profile carries a green check.

Tap Verify code and point the camera at the QR code — recognition is automatic. If the code is damaged, type the printed characters instead.

Scanning screen

Aim the frame at the code.

Authentic verdict

Brand, product, batch and scan history.
ResultMeaningDo
AuthenticGenuine, nothing unusual.Proceed.
Authentic + verified an unusual number of timesThe code has passed the brand’s ceiling — a strong sign it has been copied onto fakes.Treat with suspicion and tell the brand.
Authentic + held by another verifierSomeone else still holds custody.Ask them to transfer it to you.
Authentic + verified multiple timesYou have scanned this exact code before.Normal for your own stock; odd for a new item.
Non AuthenticThe code does not exist, or the brand has withdrawn it.Do not trust the item.
Not allowed to verify this code typeYour profile does not match the code’s type.Switch profile — the item may be fine.

Choose Verify content, then pick a file from your device or paste a public link. Certified means the file is registered and unaltered — change one character and it no longer matches. A file from your device is fingerprinted locally and never uploaded.

Certified document result

A certified document.

Requirements

RequirementDetail
Operating systemAndroid 7.0 or later.
CameraRecommended, not required. Without one, codes can always be typed in.
LocationRequired only for verifier types configured to record position. GPS hardware is optional at install time.
ConnectivityRequired. Authenticity is decided by the server.
StorageNegligible — the app keeps only its profiles and settings.
iPhone / iPadNot available. Use the web app in Safari — everything works except precise location.

Installing the Android app

  1. Install AuthPlus from Google Play: play.google.com/store/apps/details?id=com.authenticity_plus.
  2. Open the app. It goes straight to the verification home screen and provisions a profile for the device automatically.
  3. Allow camera access when first asked, and location if your organisation’s profiles require it.

Expected result. The home screen shows Verify code, Verify content and Verifiers, with “Verifying as …” naming the automatic profile.

The verification app

The scanning experience, used by customers, shops, distributors and inspectors. No account, no configuration.

Android appWeb browser
Opens onThe verification home screenThe dashboard, unless you open /verify
Camera scanningYesYes, where the browser allows camera access
Location recordingYes, preciseApproximate
Best forDaily field useOccasional checks, desktop verification of documents

Both are the same application and behave identically. Installation is covered in Installing the Android app.

Verification app home screen

Three actions, and the profile you are verifying as.
ElementWhat it does
Verify codeOpens the camera to scan a QR code, or lets you type a code by hand.
Verify contentChecks whether a file or a link is a certified document.
VerifiersManages the profiles on this device. The subtitle shows the active one — “Verifying as …”.
Grid icon (top)Switches to the AuthPlus dashboard, for users who also have an account.
Language iconSwitches between English, French and Arabic.
Sun / moon iconSwitches between light and dark appearance.

Verifier profiles

Every scan is recorded under a profile. Understanding profiles explains almost every unexpected refusal.

The first time the app opens, it creates a Public profile for the device without asking anything — named after the type and a short number, for example Public 7673. Nothing needs to be set up, and the profile carries no personal information.

Purpose. Use credentials issued by a brand — typically a Control profile for inspections, or a Reseller profile for a trade partner.

Prerequisites. A username and password given to you by the brand or the platform administrator (see Control verifiers).

  1. From the home screen, open Verifiers.
  2. Select Add.
  3. Choose the Type — for example Control.
  4. Enter the Username and Password you were given.
  5. Select Save.

Expected result. The profile appears in the list and becomes the active one. Scans are now recorded under it.

Add verifier dialog with type, username and password

Adding a Control profile.

Verifier list with the active profile checked

The active profile carries a green check.
MessageMeaningResolution
Please select a typeNo type chosen.Pick the type your credentials belong to.
Username and password are requiredA field is empty for a credential-based type.Complete both fields.
Incorrect password!The username exists but the password does not match.Re-enter carefully; ask the brand to reset it if needed.
The verifier account is not valid!No such profile exists, and this type does not allow self-creation.Check the username, and that you selected the right type.
Could not add verifierThe request did not reach the server.Check the network connection and try again.

On the Verifiers screen, tap the circle on the left of a profile card. It turns into a green check, the card is outlined, and the home screen updates to “Verifying as …”.

Use the bin icon on the profile card. This removes the profile from this device only: the account itself and every scan already recorded under it are preserved. You can add it back at any time with the same credentials.

Verifying a product

The core task: confirm that an item in your hands is genuine.

Prerequisites. A verifier profile must be active, the app needs camera permission, and you need an internet connection.

  1. Tap Verify code.
  2. Allow camera access the first time you are asked.
  3. Hold the code inside the frame. Recognition is automatic — there is no button to press.

Scanning screen with camera frame and manual entry field

Aim the frame at the code.

Authentic verdict with brand, product and batch

A genuine product.

Codes are always printed as text next to the QR symbol, so a damaged, dirty or badly lit code can still be checked. Type it into Enter code at the bottom of the scanning screen and select Verify.

A product verdict screen shows, from top to bottom:

  • The verdict — a large coloured icon and word.
  • Brand, with a green check if the brand has been verified by AuthPlus.
  • Product, Batch, and the manufacturing and expiry dates when the brand recorded them.
  • The Code itself.
  • Verifications — the item’s scan history, each line naming the verifier, the date, the number of checks, and marking the current Holder if there is one.
  • Scan another to return to the camera, and Transfer when you are the holder (Transfers & custody).

Some professional profiles require the device’s position before a scan is accepted, so that inspections can be situated. If location is switched off you are shown Unable to retrieve your location. Enable location and try again. with an Enable location button.

  1. Select Enable location and accept the system prompt.
  2. If you previously denied the permission, grant it in the device settings for AuthPlus.
  3. Go outside or near a window if no fix is obtained indoors, then scan again.

Verdict reference

Every possible outcome of scanning a product code, what it means, and what to do. This is the definitive list.

ShownMeaningWhat to do
AuthenticThe code exists, everything in its chain is active, your profile is entitled to it, and nothing about the scan is unusual.Proceed. Full product details and history are displayed.

The verdict still reads Authentic and full details are shown, but a secondary line explains why the scan deserves attention. There are exactly three such cases.

Secondary messageWhy it appearsWhat to do
Verified multiple timesYou — this same profile — have already checked this exact code before.Normal if you are re-checking your own stock. Suspicious if you are seeing the item for the first time, because it suggests a duplicate.
Held by another verifierAnother profile of your own type already holds custody of this code and has not transferred it to you.The goods may not have been formally handed over. Ask the previous holder to transfer custody (Transfers & custody).
This code has been verified an unusual number of timesThe code has passed the ceiling set by its brand — far more checks than one physical item would normally receive.Treat as a strong counterfeit signal. The original may be genuine while the code has been copied onto many fakes. Report it to the brand.

A red screen with no product details — nothing is disclosed about a code that cannot be trusted.

Secondary messageWhy it appearsWhat to do
This code does not existNo such code was ever issued. Either it is invented, or it was mistyped.Re-check the characters if you typed it. If it was scanned from a QR code, treat the item as counterfeit.
This product has been withdrawnThe code was genuine, but the brand has archived it — or archived its batch, product or brand. This is how a recall or a withdrawn batch is enforced.Do not sell or accept the item. Contact the brand: the withdrawal is deliberate.

Refusals — when the scan cannot be performed

Section titled “Refusals — when the scan cannot be performed”

These appear as a Verify failed message rather than a verdict screen, and return you to the camera. They say something about your profile, not about the item.

MessageWhy it appearsWhat to do
You are not allowed to verify this code typeThe active profile’s type does not match the code’s type — for example a Control profile scanning a Public consumer code.Switch to the matching profile (Switching the active profile) and scan again.
You are not allowed to verify a code from a different creatorYour profile is restricted to one brand owner’s codes, and this code belongs to another.Expected when you hold a brand-specific inspection profile. Use the profile issued by the right brand.
This verifier does not existThe stored profile is no longer recognised by the server.Remove the profile and add it again (Adding a professional profile).
Unable to retrieve your location…The profile requires a position and none is available.Enable location — see When location is required.
Select a verifier firstNo profile is active on the device.Open Verifiers and select or add one.
Please enter a valid codeThe manually typed code is too short.Type the full code as printed.
Camera unavailable — enter the code manuallyCamera permission was refused, or no camera is available.Grant camera access in the device settings, or use manual entry.
An error occurredAn unexpected server-side problem.Try again; if it persists, contact support with the code and the time (Support).

Non Authentic verdict screen

A code that was never issued.

Verifying assets & documents

Valuables and files are certified differently from mass-produced goods, and their verdicts use different wording.

Scanning is identical — the app recognises the kind of code automatically and shows a certificate view instead of a product view. It contains the brand, the item’s name or reference, its category, the date it was certified, and for assets the number of ownership transfers recorded.

VerdictMeaningWhat to do
CertifiedThe record is registered and its digital signature matches — nothing has been altered.Trust it. Use View document to open the certified file.
Not registeredNo certified item matches this code.Treat the certificate as invalid.
Verification failedThe record exists but does not match its signature — the data has been tampered with.Do not trust it. Report it to the brand immediately.
ArchivedThe record was withdrawn by its owner and is no longer active.Ask the brand whether the withdrawal was intentional.

Purpose. Confirm that a document you received — a certificate, a contract, a photograph — is the exact file the brand certified, even if it reached you with no code at all.

  1. From the home screen, choose Verify content.
  2. Select Choose file and pick the document from your device.
  3. The result appears at once.

Expected result. Certified if the file matches a certified record exactly; otherwise the file is not registered.

Verify content screen with file picker and link field

Choose a file, or paste a link.

Certified document result

A certified document.

Paste a public web address into Public link and select Verify. AuthPlus downloads the file and checks its fingerprint for you.

MessageMeaningResolution
URL must be a valid http(s) linkThe address is malformed or uses an unsupported scheme.Paste the full address beginning with http:// or https://.
Could not download the linkThe file is unreachable, requires a login, or the server refused.Use a publicly accessible link, or download the file and check it directly (Checking a file you already have).
No certified content for that hashThe file is not registered with AuthPlus, or it has been modified since certification.Ask the issuer for the original certified document.

Transfers & custody

How AuthPlus follows goods as they change hands — and the two different things “transfer” can mean.

The first professional profile to verify a product code becomes its holder. The holder is shown on the verdict screen, and it is how a brand can see where a given unit currently sits in its distribution chain.

Custody is tracked separately for each verifier type, so a Reseller holder and a Control holder can coexist for the same item without interfering with each other.

Purpose. Hand an item over formally — from a warehouse to a shop, or from a shop to a customer.

Prerequisites. You must currently hold the code, and the recipient must have already verified this same item with a profile of the same type — that is how they appear in the list of possible recipients.

  1. Both parties scan the item’s code.
  2. On the holder’s device, the verdict screen offers Transfer.
  3. Choose the recipient from the item’s verification history and confirm (Transfer this label to …?).

Expected result. Transfer completed. The recipient becomes the holder, and the movement is recorded permanently in the item’s history and in the brand’s operations list.

MessageMeaningResolution
This code is not held by this verifierYou are not the current holder.Only the holder can transfer. Check the verdict screen to see who holds it.
The verifiers have different typesSender and recipient profiles are of different types.Both parties must use the same type of profile — two Reseller profiles, for example.
This verifier does not existThe recipient profile is unknown to the server.Have the recipient re-add their profile, verify the item again, then retry.
Transfer failedThe request did not complete.Check connectivity and retry; if the profile requires location, enable it first.

Scan history

A record of everything you have checked with a given profile.

  1. Open Verifiers.
  2. Select the clock icon on the profile you are interested in.

Each entry shows the action (Verify or Transfer), the date and time, the result in words, the place the scan was made, and the code — which you can copy. Entries load ten at a time; select Load more to go further back.

Scan history list

Every scan made with this profile, most recent first.

Security

How AuthPlus protects accounts and codes, and what is expected of you.

MeasureDetail
Password storagePasswords are never stored, and cannot be recovered by anyone including administrators. Only a modern, deliberately slow one-way hash is kept, so a stolen database does not yield usable passwords.
Password rulesMinimum 8 characters. No further complexity is imposed — strength is your responsibility.
One-time codes6 digits, valid for 10 minutes, at most 5 attempts, single use. Requesting a new code cancels the previous one.
Automated-abuse protectionSign-in, sign-up, password reset and every public scan carry an invisible proof-of-work check that makes bulk automated attempts expensive (The invisible anti-bot check).
Role separationOrdinary users cannot reach administrative functions, and administrators cannot alter the superadministrator account.

Signing in creates a session that is renewed silently while you work, so you are not interrupted. Sessions are long-lived by design, so that field staff are not asked to sign in repeatedly.

ActionEffect on sessions
Sign outEnds the session on that device only.
Password reset (from the sign-in page)Ends every session, on every device.
Password change (from your profile)Other devices stay signed in.
Email changeSessions are unaffected.
  • Unguessable. Codes are random, drawn from a 32-character alphabet that excludes easily confused glyphs, and are 12 to 20 characters long. They are not sequential, so knowing one tells an attacker nothing about another.
  • Verified centrally. A code is meaningless on its own — authenticity is decided by the server, not by anything printed on the label.
  • Signed for assets and documents. Certificates carry a cryptographic signature over the record’s identity; altering the record breaks the signature and the verdict becomes Verification failed.
  • Fingerprinted for files. A certified document is bound to a fingerprint of its exact contents, so any modification is detectable.
  • Copy-detection. Because copying a genuine code onto many fakes cannot be prevented physically, AuthPlus detects it statistically through verification ceilings and custody conflicts (Authentic, with a warning).

Before a sign-in, a sign-up, a password reset or a public scan is accepted, your device performs a small computation that proves a real client is present. There is no puzzle, no checkbox and nothing to read.

What you may noticeExplanation
A brief delay before the button respondsNormal, particularly on older devices.
Challenge verification failedThe check expired — usually a page left open a long time. Reload and try again.
Could not fetch verification challengeThe device could not reach the server. Check connectivity.
  • Give each person their own account and their own verifier profile; never share credentials.
  • Keep the number of administrators to a minimum and review the list regularly (User management).
  • Archive accounts and verifier profiles the day someone leaves.
  • Change any initial password set for you by an administrator at first sign-in.
  • Sign out on shared or public computers — closing the tab is not enough.
  • Treat the CSV of issued codes as confidential: it lists valid codes in bulk.
  • Review Warnings and Operations on a regular schedule; nobody is emailed when something suspicious happens (Notifications).

Data & privacy

What AuthPlus records, where it goes, and how long it stays. Read this before deploying the app to customers.

Every completed scan or transfer writes one permanent line to the audit trail:

RecordedDetailVisible to
What was scannedThe code, and the item it belongs to when it is recognisedThe code’s owner, administrators
The resultAuthentic, a warning, or the reason it failedSame
WhenServer timestampSame
WhoThe verifier profileSame
The deviceA stable device identifier, plus manufacturer, model and operating systemSame
WhereNetwork address, resolved town or city, and precise coordinates when location is usedSame
SourceWhen usedPrecision
Device location (GPS)When the verifier type requires it, and permission is grantedPrecise — the actual position of the scan
Network addressOtherwiseApproximate — typically the town or the internet provider’s location
  • Uploaded files — logos, product images, certified documents — are stored unchanged, in their original form. They are not resized or re-encoded, so any metadata they contain (including photograph location data) is preserved.
  • Certified content is additionally fingerprinted, and that fingerprint is what verification compares.
  • When you verify a file from your own device, the file is not uploaded — only its fingerprint is sent. Verifying a link is different: the server downloads the file to fingerprint it.

AuthPlus is built to preserve evidence. The audit trail, in particular, is never edited or removed by the application.

RecordCan be removed?
Operations (verifications and transfers)No — permanent
Brands, products, assets, contents, items, issuances, codesArchived only, never deleted
User accountsArchived only
WarningsClosed, not deleted
Verifier accountsArchived only
Code types, print templates, verifier typesArchived only
Generated label documentsYes — deleted along with the stored file
Prohibited-name entriesYes

Only two things can be removed outright, and neither is a record of anything: a generated PDF or CSV, which you can produce again at any time, and an entry on the prohibited-name blocklist. Everything else is archived.

Records are otherwise kept indefinitely: AuthPlus applies no automatic retention limit, and there is no self-service account deletion. Erasure requests are handled manually by the platform operator.

StoredWhy
A device identifierIdentifies the automatic verifier profile so scan history is continuous.
Verifier profiles and the active oneSo you do not re-enter credentials at every launch.
Sign-in tokensKeeps you signed in to the dashboard.
Language, theme, and the administrator’s owner filterPreferences, per device.

AuthPlus uses no analytics, no advertising and no tracking cookies, and loads no third-party fonts or scripts. The only external call made by the app is the location lookup described in How location is determined.

Removing a verifier profile in the app removes it from that device only; the account and its history remain on the server.

Codes can be exported as CSV per issuance (Labels & exports), and label sheets as PDF. There is no bulk export of operations, catalogue or account data from the interface — an operator with database access can produce one on request.

Notifications

What AuthPlus tells you, and — importantly — what it does not.

AuthPlus sends exactly one kind of email: a one-time code. Every message expires after 10 minutes and asks for nothing else.

TriggerSubjectSent to
Signing upVerify your AuthPlus emailThe address being registered
Signing in with a codeYour AuthPlus sign-in codeYour address
Forgotten passwordReset your AuthPlus passwordYour address
Changing your emailConfirm your new AuthPlus emailThe new address
Changing your password by codeYour AuthPlus password-change codeYour address
SignalWhereMeaning
Red count on WarningsSidebarUnresolved warnings. Hidden when there are none.
Red count on BrandsSidebar, administrators onlyBrand verification requests awaiting a decision.
Brief messagesCorner of the screenConfirmation or failure of the action you just performed. They disappear after a few seconds.
Status chipsBrand pagesVerified, pending or rejected badge status.

Troubleshooting

Symptoms, causes and resolutions, grouped by where the problem appears.

SymptomLikely causeResolution
Invalid email or passwordWrong credentials, or the address is not registered.Re-type carefully. Use Forgot password, or sign in with an email code instead.
Account is not activeThe account has been archived by an administrator.Contact your administrator; only they can restore it (Archiving an account).
No code arrivesWrong address, spam filtering, or the address is not registered.Check spam. Confirm the address. For a sign-in code, remember the request always reports success even for unknown addresses.
Invalid or expired codeMore than 10 minutes elapsed, five wrong attempts, or an older code was used.Request a fresh code and use the newest email.
Challenge verification failedThe page has been open too long.Reload and retry.
Signed out unexpectedlySomeone performed a password reset on the account.Sign in again. If you did not request it, tell your administrator immediately.
SymptomLikely causeResolution
You are not allowed to verify this code typeThe active profile does not match the code’s tier.Switch profile (Switching the active profile). The item is not necessarily suspect.
Select a verifier firstNo profile is active on the device.Open Verifiers and select one.
Camera shows nothing, or is refusedCamera permission denied, or another app holds the camera.Grant camera access in the device settings; close other camera apps; use manual entry meanwhile.
The QR will not readPrint too small, poor contrast, glare, or a damaged label.Improve lighting, hold steady at 10–15 cm, or type the printed code instead.
Stuck on Enable locationThe profile requires a position and none is available.Enable location, allow the permission, and move where the sky is visible (When location is required).
Everything times outNo connectivity, or the device cannot reach the server.Verification always needs a connection. Check the network; on a private installation confirm the device is on the right one.
Verdict says withdrawn for stock you believe is fineThe brand, product, batch, issuance or the owner’s account has been archived.Ask the brand — the withdrawal is deliberate (Archiving — nothing is ever deleted).
SymptomLikely causeResolution
Records are missingThe status filter is on Active, or (administrators) the owner filter is on the wrong owner.Switch the status filter to see archived records; check the owner selector (The owner filter).
Times look wrongNo timezone set on your profile.Set it in Profile (Name and timezone).
Quantity must be between 1 and 1000Too many codes requested at once.Split the run into several issuances.
Please upload an image file / attachments must be images or PDFsUnsupported file type.Convert to PNG, JPEG or PDF, under 8 MB.
Upload fails silently on a large fileThe file exceeds 8 MB.Compress or resize it.
No print template availableNo label template is configured on the platform.Ask an administrator (Platform configuration).
Object storage is not configuredServer-side storage is unavailable, so files and documents cannot be saved.This is an installation problem — contact whoever operates your AuthPlus server.
The map is emptyNo operations match the filters, or none carry a position.Widen the date range and clear filters; remember approximate locations depend on the network.
A page briefly shows a generic errorTransient server or connectivity problem.Use the retry action. If it persists, note the time and contact support.

Frequently asked questions

Do customers need an account to verify a product?
No. The verification app works with no account and no registration, in the mobile app or a browser.
Does verification work without an internet connection?
No. Authenticity is decided by the server, so a connection is always required.
Can I verify a product without the mobile app?
Yes — open the AuthPlus website and choose the verification area. Everything except precise location works the same way.
What if the QR code is damaged?
Type the code printed beside it. Codes deliberately avoid the characters most often confused.
Someone scanned my product before me. Is it fake?
Not necessarily — a batch is normally checked by the factory, the distributor and the shop. What matters is the pattern: many checks, in distant places, in a short time.
How many codes can I issue at once?
Up to 1000 per issuance. Larger runs are split into several issuances, which also gives finer recall control.
Can I reuse or re-issue a code?
No. Every code is unique and permanent. Issue new codes instead.
Can I change a product's name after codes are printed?
Yes — verdict screens show the current details. What is printed on the physical label does not change, so keep the two consistent.
What size should the printed QR be?
Test before the full run. Print one sheet at the final size, on the final material, and scan it with an ordinary phone (Labels & exports).
Can I stop a single code without affecting the batch?
Yes. Archive that one code. Archiving the issuance, item, product or brand affects everything beneath it.
I forgot my password.
Use Forgot password, or sign in with a one-time email code (Signing in).
Can an administrator see my password?
No. Passwords are stored only as an irreversible hash. An administrator can set a new one for an account they create, but cannot read an existing one.
Can two people share one account?
Technically yes, but do not: the audit trail attributes every action to the account, so sharing destroys accountability.
What happens to my products if my account is archived?
They stop verifying — every code you own returns withdrawn until the account is restored (Archiving an account).
How do I get the Admin role?
Another administrator must grant it. It cannot be requested from the interface.
Is my document uploaded when I verify a file?
No. The fingerprint is computed on your own device and only that value is sent. Checking a link is different: there the server downloads the file to hash it.
Can I delete a record?
Records are archived, not deleted, so the audit trail stays intact. Archived records stop verifying and can be restored.
Who can see where a scan happened?
The owner of the scanned code, and administrators. Verifiers see their own history.
Will I be notified if one of my codes is abused?
Not by email or push — a warning appears in the dashboard and the sidebar badge (Notifications).

Glossary

Archive
To withdraw a record without deleting it. Archived records stop verifying and can be restored (Archiving — nothing is ever deleted).
Asset
A unique valuable registered individually and carrying a signed ownership certificate.
Authenticity code (code)
The unique string, printed as text and as a QR symbol, that identifies one protected unit.
Batch
An item under a product: one production run, to which codes are attached.
Brand
The top of the protection chain; the name shown to anyone verifying.
Code type
The tier of a code — Public, Reseller or Control — which decides who may verify it.
Content
A certified file: a document, certificate or media item bound to a fingerprint of its contents.
Custody / holder
Which verifier profile currently holds an item in the field. Moved by a transfer in the app (Transfers & custody).
Fingerprint
A value computed from a file's exact contents. If the file changes, the fingerprint no longer matches.
Issuance
One act of minting codes for an item, and the unit at which codes are printed and withdrawn.
Item
A concrete unit: a batch of a product, one individual valuable, or one document entry.
Operation
One recorded verification or transfer — a line in the audit trail.
Over-verified
A code checked more times than its ceiling allows; the principal automated counterfeit signal.
Owner
The account a record belongs to, and the boundary of who can see it.
Owner filter
The administrator control that chooses whose data every screen shows (The owner filter).
Ownership transfer
Moving a code from one AuthPlus account to another, in the dashboard. Distinct from custody.
Product
A manufactured good produced in quantity, organised into batches.
Subject
The generic term for a product, an asset category or a content category.
Superadministrator
The platform operator's account, which configures code types, templates and verifier types.
Verification ceiling
The number of scans a code may receive before a warning is raised (Your verification ceilings).
Verifier
The identity under which a scan is recorded — a device profile, not a dashboard account.
Verifier type
The template governing a verifier's behaviour: which codes it may check, whether it self-provisions, whether it needs location.
Verification badge
The green check displayed beside a brand whose identity AuthPlus has confirmed (Brand verification).
Warning
An automatic alert on suspicious activity, awaiting a human decision (Warnings, Moderation).

Support

Getting help, and what to include so that help is fast.

  1. Check §38 Troubleshooting — the majority of reports match an entry there.
  2. Reproduce the problem once more and note the exact wording of any message.
  3. Confirm whether it affects one record, one device, or everyone.
DetailWhy it matters
The exact messageDistinguishes between a dozen similar-looking causes.
Date, time and your timezoneLets the team find the corresponding record.
The code, brand or record involvedIdentifies exactly what was affected.
The account and role you were usingMany behaviours are role-dependent.
Web or mobile app, and the deviceCamera, location and storage issues are platform-specific.
The version at the bottom of the sidebarConfirms which release you are running.
A screenshotFaster than any description.
  • Questions about your own catalogue, codes or account — your organisation’s AuthPlus administrator, who can see your records and act on them directly.
  • Everything else — platform faults, installation and configuration questions, and suspected security problems — write to contact@authenticity-plus.com.