Guía del verificador
Instalar la aplicación, escanear un código, leer el veredicto, gestionar perfiles y custodia.
Contenido
- Introduction
- Core concepts
- Getting started
- Requirements
- Installing the Android app
- The verification app
- Verifier profiles
- Verifying a product
- Verdict reference
- Verifying assets & documents
- Transfers & custody
- Scan history
- Security
- Data & privacy
- Notifications
- Troubleshooting
- Frequently asked questions
- Glossary
- Support
Introduction
What AuthPlus does
Section titled “What AuthPlus does”Counterfeiting works because a buyer cannot tell a real item from a convincing copy. AuthPlus closes that gap. A brand registers what it produces, and AuthPlus mints a unique, tamper-proof code for every unit. The code is printed on the product, its label or its certificate. Anyone holding the item can scan that code and receive an immediate, unambiguous answer: Authentic, Authentic with a warning, or Non Authentic.
Every scan is recorded, so the brand sees where and when its products are being checked, and unusual patterns — the same code verified far more often than a single physical item ever could be — surface automatically as warnings.
Protect
Register brands, products, valuables and documents, then issue unique authenticity codes for them.
Verify
Anyone can confirm authenticity in seconds with the mobile app or a web browser — no account required.
Monitor
Follow every verification and transfer on a live audit trail and map, with automatic alerts on abuse.
AuthPlus is delivered as two connected experiences that share one account system:
- The dashboard (
/dash) — a web workspace where brand owners register their catalogue, issue codes, print labels and monitor activity. - The verification app (
/verify) — a deliberately simple scanning experience, available as an Android app and in any web browser, used in shops, at customs, or by end customers.
Conventions used in this document
Section titled “Conventions used in this document”- Names of on-screen elements appear like this: Issue Codes. They match the English interface exactly; in French or Arabic the label is translated but the position is identical.
- Sequences of navigation are written Products → New.
- Technical values — addresses, file names, settings — appear as
code. - Numbered procedures always follow the same shape: purpose, prerequisites, the steps, then the expected result.
- A role badge next to a heading means the feature is limited to that role: Standard user Admin Superadmin Verifier
Three kinds of callout are used:
Core concepts
The protection chain
Section titled “The protection chain”Everything you protect in AuthPlus follows the same five-level chain. Understanding it makes every screen in the dashboard predictable, because each level is simply a list of the level below it.
| Level | What it is | Example |
|---|---|---|
| 1. Brand | The name behind your items. Everything you register belongs to a brand. | Aurora Watches |
| 2. Subject Product · Asset · Content | The thing you protect, or a category of them. Its type decides how it is verified. | Aurora Chrono 42 |
| 3. Item | A concrete unit: a production batch, one individual valuable, or one document entry. | Batch AC42-2026-A |
| 4. Issuance | One act of minting codes for an item. An item can have several issuances over time. | 10 Public codes, 30 July 2026 |
| 5. Code | A single unique authenticity code, printed as text and as a QR code. | 2H7KLM4GUEXDVM |
In the dashboard you walk down this chain by clicking: a brand’s products, a product’s batches, a batch’s issuances, an issuance’s codes. Breadcrumbs at the top of each screen show you where you are and let you climb back up.
The three kinds of subject
Section titled “The three kinds of subject”A subject’s type is chosen when you create it and cannot be changed afterwards. It determines which section of the dashboard the subject lives in, how codes are issued for it, and what a verifier sees when it is scanned.
| Products | Assets | Contents | |
|---|---|---|---|
| For | Manufactured goods produced in quantity | Unique valuables: art, jewellery, collectibles | Files: certificates, official documents, media |
| Item means | A production batch | One individual piece | One document entry |
| Codes per item | Many — one per physical unit | Normally one | One per uploaded file |
| Issued by | Choosing a quantity | Choosing a quantity | Uploading files — each file becomes one code |
| Verified by | Scanning the printed code | Scanning the code on the certificate | Scanning the code, or checking the file itself |
| Verifier sees | Brand, product, batch, dates, scan history | An ownership certificate with its provenance | A certification record and the document |
Authenticity codes and code types
Section titled “Authenticity codes and code types”A code is a short random string, unique across the platform, printed as text and encoded in a QR code. Codes are not sequential and cannot be guessed from one another.
Every code belongs to a code type, chosen at issuance. Code types are configured centrally for the whole platform and typically follow the distribution chain:
| Code type | Intended for | Typical placement |
|---|---|---|
| Public | End customers. The default. | Visible on the product or its packaging |
| Reseller | Distributors and retail partners | On the carton or delivery documents |
| Control | Internal inspection and enforcement | Hidden or restricted placement |
Verifiers and verifier types
Section titled “Verifiers and verifier types”A verifier is the identity under which a scan is recorded — a shop, an employee, an inspector, or simply an anonymous consumer device. Verifiers are not dashboard user accounts; they exist so that an item’s history is meaningful, and so that custody can be tracked as goods move.
Each verifier belongs to a verifier type, which decides how it behaves:
- Public — created automatically on first launch of the app. No credentials, no setup. This is what an ordinary customer uses without ever noticing.
- Reseller — for trade partners; also self-provisioning, but tied to reseller codes.
- Control — restricted inspection accounts. These are created by the platform administrator and handed out with a username and password (see Control verifiers).
Verifier types can also require the device’s location before a scan is accepted, restrict a verifier to codes created by a particular owner, or fill in the verifier’s profile automatically from the device.
What a verification produces
Section titled “What a verification produces”Every scan — successful or not — creates an operation: a permanent line in the audit trail recording what was scanned, by which verifier, when, from where, and with what result. Operations are what feed the dashboard’s statistics, the map, and the warning system.
The verdict falls into one of three classes:
| Verdict | Meaning | What to do |
|---|---|---|
| Authentic | The code exists, is active, and nothing about the scan is unusual. | Proceed with confidence. |
| Authentic, with a warning | The code is genuine, but the circumstances deserve attention — most often because it has been verified more times than a single item plausibly would be. | Treat with care; the item may be genuine while its code has been copied. |
| Non Authentic | The code does not exist, or it has been blocked or archived. | Do not trust the item. Report it to the brand. |
The exhaustive list of outcomes, with the exact message shown for each, is in §12 Verdict reference.
Archiving — nothing is ever deleted
Section titled “Archiving — nothing is ever deleted”AuthPlus is an evidence system, so records are not destroyed. Instead of deleting a brand, product, item, issuance, code or verifier, you archive it. An archived record stays visible (behind the Archived filter), keeps its history, and can be restored.
Archiving has one immediate, deliberate consequence:
Use it deliberately: archiving a brand silently disables every code beneath it. When you only need to stop one batch, archive that issuance rather than anything higher up the chain.
Getting started
Set up the app
Section titled “Set up the app”- Install AuthPlus from Google Play, or open
/verifyin a browser. - Open it. A verifier profile is created for you automatically — the home screen shows “Verifying as …”. Nothing to configure.
- If a brand gave you credentials (a Control profile, say), add them: Verifiers → Add → choose the type → username and password → Save. Tap the circle on a card to switch profile.


Scan and read the result
Section titled “Scan and read the result”Tap Verify code and point the camera at the QR code — recognition is automatic. If the code is damaged, type the printed characters instead.


| Result | Meaning | Do |
|---|---|---|
| Authentic | Genuine, nothing unusual. | Proceed. |
| Authentic + verified an unusual number of times | The code has passed the brand’s ceiling — a strong sign it has been copied onto fakes. | Treat with suspicion and tell the brand. |
| Authentic + held by another verifier | Someone else still holds custody. | Ask them to transfer it to you. |
| Authentic + verified multiple times | You have scanned this exact code before. | Normal for your own stock; odd for a new item. |
| Non Authentic | The code does not exist, or the brand has withdrawn it. | Do not trust the item. |
| Not allowed to verify this code type | Your profile does not match the code’s type. | Switch profile — the item may be fine. |
Check a document
Section titled “Check a document”Choose Verify content, then pick a file from your device or paste a public link. Certified means the file is registered and unaltered — change one character and it no longer matches. A file from your device is fingerprinted locally and never uploaded.

Requirements
| Requirement | Detail |
|---|---|
| Operating system | Android 7.0 or later. |
| Camera | Recommended, not required. Without one, codes can always be typed in. |
| Location | Required only for verifier types configured to record position. GPS hardware is optional at install time. |
| Connectivity | Required. Authenticity is decided by the server. |
| Storage | Negligible — the app keeps only its profiles and settings. |
| iPhone / iPad | Not available. Use the web app in Safari — everything works except precise location. |
Installing the Android app
- Install AuthPlus from Google Play: play.google.com/store/apps/details?id=com.authenticity_plus.
- Open the app. It goes straight to the verification home screen and provisions a profile for the device automatically.
- Allow camera access when first asked, and location if your organisation’s profiles require it.
Expected result. The home screen shows Verify code, Verify content and Verifiers, with “Verifying as …” naming the automatic profile.
The verification app
The scanning experience, used by customers, shops, distributors and inspectors. No account, no configuration.
Where to find it
Section titled “Where to find it”| Android app | Web browser | |
|---|---|---|
| Opens on | The verification home screen | The dashboard, unless you open /verify |
| Camera scanning | Yes | Yes, where the browser allows camera access |
| Location recording | Yes, precise | Approximate |
| Best for | Daily field use | Occasional checks, desktop verification of documents |
Both are the same application and behave identically. Installation is covered in Installing the Android app.
The home screen
Section titled “The home screen”
| Element | What it does |
|---|---|
| Verify code | Opens the camera to scan a QR code, or lets you type a code by hand. |
| Verify content | Checks whether a file or a link is a certified document. |
| Verifiers | Manages the profiles on this device. The subtitle shows the active one — “Verifying as …”. |
| Grid icon (top) | Switches to the AuthPlus dashboard, for users who also have an account. |
| Language icon | Switches between English, French and Arabic. |
| Sun / moon icon | Switches between light and dark appearance. |
Verifier profiles
Every scan is recorded under a profile. Understanding profiles explains almost every unexpected refusal.
Your automatic profile
Section titled “Your automatic profile”The first time the app opens, it creates a Public profile for the device without asking anything — named after the type and a short number, for example Public 7673. Nothing needs to be set up, and the profile carries no personal information.
Adding a professional profile
Section titled “Adding a professional profile”Purpose. Use credentials issued by a brand — typically a Control profile for inspections, or a Reseller profile for a trade partner.
Prerequisites. A username and password given to you by the brand or the platform administrator (see Control verifiers).
- From the home screen, open Verifiers.
- Select Add.
- Choose the Type — for example Control.
- Enter the Username and Password you were given.
- Select Save.
Expected result. The profile appears in the list and becomes the active one. Scans are now recorded under it.


Common errors
Section titled “Common errors”| Message | Meaning | Resolution |
|---|---|---|
| Please select a type | No type chosen. | Pick the type your credentials belong to. |
| Username and password are required | A field is empty for a credential-based type. | Complete both fields. |
| Incorrect password! | The username exists but the password does not match. | Re-enter carefully; ask the brand to reset it if needed. |
| The verifier account is not valid! | No such profile exists, and this type does not allow self-creation. | Check the username, and that you selected the right type. |
| Could not add verifier | The request did not reach the server. | Check the network connection and try again. |
Switching the active profile
Section titled “Switching the active profile”On the Verifiers screen, tap the circle on the left of a profile card. It turns into a green check, the card is outlined, and the home screen updates to “Verifying as …”.
Removing a profile
Section titled “Removing a profile”Use the bin icon on the profile card. This removes the profile from this device only: the account itself and every scan already recorded under it are preserved. You can add it back at any time with the same credentials.
Verifying a product
The core task: confirm that an item in your hands is genuine.
Scanning a QR code
Section titled “Scanning a QR code”Prerequisites. A verifier profile must be active, the app needs camera permission, and you need an internet connection.
- Tap Verify code.
- Allow camera access the first time you are asked.
- Hold the code inside the frame. Recognition is automatic — there is no button to press.


Entering a code by hand
Section titled “Entering a code by hand”Codes are always printed as text next to the QR symbol, so a damaged, dirty or badly lit code can still be checked. Type it into Enter code at the bottom of the scanning screen and select Verify.
Reading the result
Section titled “Reading the result”A product verdict screen shows, from top to bottom:
- The verdict — a large coloured icon and word.
- Brand, with a green check if the brand has been verified by AuthPlus.
- Product, Batch, and the manufacturing and expiry dates when the brand recorded them.
- The Code itself.
- Verifications — the item’s scan history, each line naming the verifier, the date, the number of checks, and marking the current Holder if there is one.
- Scan another to return to the camera, and Transfer when you are the holder (Transfers & custody).
When location is required
Section titled “When location is required”Some professional profiles require the device’s position before a scan is accepted, so that inspections can be situated. If location is switched off you are shown Unable to retrieve your location. Enable location and try again. with an Enable location button.
- Select Enable location and accept the system prompt.
- If you previously denied the permission, grant it in the device settings for AuthPlus.
- Go outside or near a window if no fix is obtained indoors, then scan again.
Verdict reference
Every possible outcome of scanning a product code, what it means, and what to do. This is the definitive list.
Authentic
Section titled “Authentic”| Shown | Meaning | What to do |
|---|---|---|
| Authentic | The code exists, everything in its chain is active, your profile is entitled to it, and nothing about the scan is unusual. | Proceed. Full product details and history are displayed. |
Authentic, with a warning
Section titled “Authentic, with a warning”The verdict still reads Authentic and full details are shown, but a secondary line explains why the scan deserves attention. There are exactly three such cases.
| Secondary message | Why it appears | What to do |
|---|---|---|
| Verified multiple times | You — this same profile — have already checked this exact code before. | Normal if you are re-checking your own stock. Suspicious if you are seeing the item for the first time, because it suggests a duplicate. |
| Held by another verifier | Another profile of your own type already holds custody of this code and has not transferred it to you. | The goods may not have been formally handed over. Ask the previous holder to transfer custody (Transfers & custody). |
| This code has been verified an unusual number of times | The code has passed the ceiling set by its brand — far more checks than one physical item would normally receive. | Treat as a strong counterfeit signal. The original may be genuine while the code has been copied onto many fakes. Report it to the brand. |
Non Authentic
Section titled “Non Authentic”A red screen with no product details — nothing is disclosed about a code that cannot be trusted.
| Secondary message | Why it appears | What to do |
|---|---|---|
| This code does not exist | No such code was ever issued. Either it is invented, or it was mistyped. | Re-check the characters if you typed it. If it was scanned from a QR code, treat the item as counterfeit. |
| This product has been withdrawn | The code was genuine, but the brand has archived it — or archived its batch, product or brand. This is how a recall or a withdrawn batch is enforced. | Do not sell or accept the item. Contact the brand: the withdrawal is deliberate. |
Refusals — when the scan cannot be performed
Section titled “Refusals — when the scan cannot be performed”These appear as a Verify failed message rather than a verdict screen, and return you to the camera. They say something about your profile, not about the item.
| Message | Why it appears | What to do |
|---|---|---|
| You are not allowed to verify this code type | The active profile’s type does not match the code’s type — for example a Control profile scanning a Public consumer code. | Switch to the matching profile (Switching the active profile) and scan again. |
| You are not allowed to verify a code from a different creator | Your profile is restricted to one brand owner’s codes, and this code belongs to another. | Expected when you hold a brand-specific inspection profile. Use the profile issued by the right brand. |
| This verifier does not exist | The stored profile is no longer recognised by the server. | Remove the profile and add it again (Adding a professional profile). |
| Unable to retrieve your location… | The profile requires a position and none is available. | Enable location — see When location is required. |
| Select a verifier first | No profile is active on the device. | Open Verifiers and select or add one. |
| Please enter a valid code | The manually typed code is too short. | Type the full code as printed. |
| Camera unavailable — enter the code manually | Camera permission was refused, or no camera is available. | Grant camera access in the device settings, or use manual entry. |
| An error occurred | An unexpected server-side problem. | Try again; if it persists, contact support with the code and the time (Support). |

Verifying assets & documents
Valuables and files are certified differently from mass-produced goods, and their verdicts use different wording.
Scanning an asset or a document code
Section titled “Scanning an asset or a document code”Scanning is identical — the app recognises the kind of code automatically and shows a certificate view instead of a product view. It contains the brand, the item’s name or reference, its category, the date it was certified, and for assets the number of ownership transfers recorded.
| Verdict | Meaning | What to do |
|---|---|---|
| Certified | The record is registered and its digital signature matches — nothing has been altered. | Trust it. Use View document to open the certified file. |
| Not registered | No certified item matches this code. | Treat the certificate as invalid. |
| Verification failed | The record exists but does not match its signature — the data has been tampered with. | Do not trust it. Report it to the brand immediately. |
| Archived | The record was withdrawn by its owner and is no longer active. | Ask the brand whether the withdrawal was intentional. |
Checking a file you already have
Section titled “Checking a file you already have”Purpose. Confirm that a document you received — a certificate, a contract, a photograph — is the exact file the brand certified, even if it reached you with no code at all.
- From the home screen, choose Verify content.
- Select Choose file and pick the document from your device.
- The result appears at once.
Expected result. Certified if the file matches a certified record exactly; otherwise the file is not registered.


Checking a link
Section titled “Checking a link”Paste a public web address into Public link and select Verify. AuthPlus downloads the file and checks its fingerprint for you.
| Message | Meaning | Resolution |
|---|---|---|
| URL must be a valid http(s) link | The address is malformed or uses an unsupported scheme. | Paste the full address beginning with http:// or https://. |
| Could not download the link | The file is unreachable, requires a login, or the server refused. | Use a publicly accessible link, or download the file and check it directly (Checking a file you already have). |
| No certified content for that hash | The file is not registered with AuthPlus, or it has been modified since certification. | Ask the issuer for the original certified document. |
Transfers & custody
How AuthPlus follows goods as they change hands — and the two different things “transfer” can mean.
What custody means
Section titled “What custody means”The first professional profile to verify a product code becomes its holder. The holder is shown on the verdict screen, and it is how a brand can see where a given unit currently sits in its distribution chain.
Custody is tracked separately for each verifier type, so a Reseller holder and a Control holder can coexist for the same item without interfering with each other.
Transferring custody
Section titled “Transferring custody”Purpose. Hand an item over formally — from a warehouse to a shop, or from a shop to a customer.
Prerequisites. You must currently hold the code, and the recipient must have already verified this same item with a profile of the same type — that is how they appear in the list of possible recipients.
- Both parties scan the item’s code.
- On the holder’s device, the verdict screen offers Transfer.
- Choose the recipient from the item’s verification history and confirm (Transfer this label to …?).
Expected result. Transfer completed. The recipient becomes the holder, and the movement is recorded permanently in the item’s history and in the brand’s operations list.
Common errors
Section titled “Common errors”| Message | Meaning | Resolution |
|---|---|---|
| This code is not held by this verifier | You are not the current holder. | Only the holder can transfer. Check the verdict screen to see who holds it. |
| The verifiers have different types | Sender and recipient profiles are of different types. | Both parties must use the same type of profile — two Reseller profiles, for example. |
| This verifier does not exist | The recipient profile is unknown to the server. | Have the recipient re-add their profile, verify the item again, then retry. |
| Transfer failed | The request did not complete. | Check connectivity and retry; if the profile requires location, enable it first. |
Scan history
A record of everything you have checked with a given profile.
- Open Verifiers.
- Select the clock icon on the profile you are interested in.
Each entry shows the action (Verify or Transfer), the date and time, the result in words, the place the scan was made, and the code — which you can copy. Entries load ten at a time; select Load more to go further back.

Security
How AuthPlus protects accounts and codes, and what is expected of you.
How your account is protected
Section titled “How your account is protected”| Measure | Detail |
|---|---|
| Password storage | Passwords are never stored, and cannot be recovered by anyone including administrators. Only a modern, deliberately slow one-way hash is kept, so a stolen database does not yield usable passwords. |
| Password rules | Minimum 8 characters. No further complexity is imposed — strength is your responsibility. |
| One-time codes | 6 digits, valid for 10 minutes, at most 5 attempts, single use. Requesting a new code cancels the previous one. |
| Automated-abuse protection | Sign-in, sign-up, password reset and every public scan carry an invisible proof-of-work check that makes bulk automated attempts expensive (The invisible anti-bot check). |
| Role separation | Ordinary users cannot reach administrative functions, and administrators cannot alter the superadministrator account. |
Sessions and devices
Section titled “Sessions and devices”Signing in creates a session that is renewed silently while you work, so you are not interrupted. Sessions are long-lived by design, so that field staff are not asked to sign in repeatedly.
| Action | Effect on sessions |
|---|---|
| Sign out | Ends the session on that device only. |
| Password reset (from the sign-in page) | Ends every session, on every device. |
| Password change (from your profile) | Other devices stay signed in. |
| Email change | Sessions are unaffected. |
What makes a code hard to forge
Section titled “What makes a code hard to forge”- Unguessable. Codes are random, drawn from a 32-character alphabet that excludes easily confused glyphs, and are 12 to 20 characters long. They are not sequential, so knowing one tells an attacker nothing about another.
- Verified centrally. A code is meaningless on its own — authenticity is decided by the server, not by anything printed on the label.
- Signed for assets and documents. Certificates carry a cryptographic signature over the record’s identity; altering the record breaks the signature and the verdict becomes Verification failed.
- Fingerprinted for files. A certified document is bound to a fingerprint of its exact contents, so any modification is detectable.
- Copy-detection. Because copying a genuine code onto many fakes cannot be prevented physically, AuthPlus detects it statistically through verification ceilings and custody conflicts (Authentic, with a warning).
The invisible anti-bot check
Section titled “The invisible anti-bot check”Before a sign-in, a sign-up, a password reset or a public scan is accepted, your device performs a small computation that proves a real client is present. There is no puzzle, no checkbox and nothing to read.
| What you may notice | Explanation |
|---|---|
| A brief delay before the button responds | Normal, particularly on older devices. |
| Challenge verification failed | The check expired — usually a page left open a long time. Reload and try again. |
| Could not fetch verification challenge | The device could not reach the server. Check connectivity. |
Good practice for your organisation
Section titled “Good practice for your organisation”- Give each person their own account and their own verifier profile; never share credentials.
- Keep the number of administrators to a minimum and review the list regularly (User management).
- Archive accounts and verifier profiles the day someone leaves.
- Change any initial password set for you by an administrator at first sign-in.
- Sign out on shared or public computers — closing the tab is not enough.
- Treat the CSV of issued codes as confidential: it lists valid codes in bulk.
- Review Warnings and Operations on a regular schedule; nobody is emailed when something suspicious happens (Notifications).
Data & privacy
What AuthPlus records, where it goes, and how long it stays. Read this before deploying the app to customers.
What a verification records
Section titled “What a verification records”Every completed scan or transfer writes one permanent line to the audit trail:
| Recorded | Detail | Visible to |
|---|---|---|
| What was scanned | The code, and the item it belongs to when it is recognised | The code’s owner, administrators |
| The result | Authentic, a warning, or the reason it failed | Same |
| When | Server timestamp | Same |
| Who | The verifier profile | Same |
| The device | A stable device identifier, plus manufacturer, model and operating system | Same |
| Where | Network address, resolved town or city, and precise coordinates when location is used | Same |
How location is determined
Section titled “How location is determined”| Source | When used | Precision |
|---|---|---|
| Device location (GPS) | When the verifier type requires it, and permission is granted | Precise — the actual position of the scan |
| Network address | Otherwise | Approximate — typically the town or the internet provider’s location |
Files and documents
Section titled “Files and documents”- Uploaded files — logos, product images, certified documents — are stored unchanged, in their original form. They are not resized or re-encoded, so any metadata they contain (including photograph location data) is preserved.
- Certified content is additionally fingerprinted, and that fingerprint is what verification compares.
- When you verify a file from your own device, the file is not uploaded — only its fingerprint is sent. Verifying a link is different: the server downloads the file to fingerprint it.
Retention, archiving and deletion
Section titled “Retention, archiving and deletion”AuthPlus is built to preserve evidence. The audit trail, in particular, is never edited or removed by the application.
| Record | Can be removed? |
|---|---|
| Operations (verifications and transfers) | No — permanent |
| Brands, products, assets, contents, items, issuances, codes | Archived only, never deleted |
| User accounts | Archived only |
| Warnings | Closed, not deleted |
| Verifier accounts | Archived only |
| Code types, print templates, verifier types | Archived only |
| Generated label documents | Yes — deleted along with the stored file |
| Prohibited-name entries | Yes |
Only two things can be removed outright, and neither is a record of anything: a generated PDF or CSV, which you can produce again at any time, and an entry on the prohibited-name blocklist. Everything else is archived.
Records are otherwise kept indefinitely: AuthPlus applies no automatic retention limit, and there is no self-service account deletion. Erasure requests are handled manually by the platform operator.
What is stored on your device
Section titled “What is stored on your device”| Stored | Why |
|---|---|
| A device identifier | Identifies the automatic verifier profile so scan history is continuous. |
| Verifier profiles and the active one | So you do not re-enter credentials at every launch. |
| Sign-in tokens | Keeps you signed in to the dashboard. |
| Language, theme, and the administrator’s owner filter | Preferences, per device. |
AuthPlus uses no analytics, no advertising and no tracking cookies, and loads no third-party fonts or scripts. The only external call made by the app is the location lookup described in How location is determined.
Removing a verifier profile in the app removes it from that device only; the account and its history remain on the server.
Getting your data out
Section titled “Getting your data out”Codes can be exported as CSV per issuance (Labels & exports), and label sheets as PDF. There is no bulk export of operations, catalogue or account data from the interface — an operator with database access can produce one on request.
Notifications
What AuthPlus tells you, and — importantly — what it does not.
Emails
Section titled “Emails”AuthPlus sends exactly one kind of email: a one-time code. Every message expires after 10 minutes and asks for nothing else.
| Trigger | Subject | Sent to |
|---|---|---|
| Signing up | Verify your AuthPlus email | The address being registered |
| Signing in with a code | Your AuthPlus sign-in code | Your address |
| Forgotten password | Reset your AuthPlus password | Your address |
| Changing your email | Confirm your new AuthPlus email | The new address |
| Changing your password by code | Your AuthPlus password-change code | Your address |
In the interface
Section titled “In the interface”| Signal | Where | Meaning |
|---|---|---|
| Red count on Warnings | Sidebar | Unresolved warnings. Hidden when there are none. |
| Red count on Brands | Sidebar, administrators only | Brand verification requests awaiting a decision. |
| Brief messages | Corner of the screen | Confirmation or failure of the action you just performed. They disappear after a few seconds. |
| Status chips | Brand pages | Verified, pending or rejected badge status. |
Troubleshooting
Symptoms, causes and resolutions, grouped by where the problem appears.
Signing in and accounts
Section titled “Signing in and accounts”| Symptom | Likely cause | Resolution |
|---|---|---|
| Invalid email or password | Wrong credentials, or the address is not registered. | Re-type carefully. Use Forgot password, or sign in with an email code instead. |
| Account is not active | The account has been archived by an administrator. | Contact your administrator; only they can restore it (Archiving an account). |
| No code arrives | Wrong address, spam filtering, or the address is not registered. | Check spam. Confirm the address. For a sign-in code, remember the request always reports success even for unknown addresses. |
| Invalid or expired code | More than 10 minutes elapsed, five wrong attempts, or an older code was used. | Request a fresh code and use the newest email. |
| Challenge verification failed | The page has been open too long. | Reload and retry. |
| Signed out unexpectedly | Someone performed a password reset on the account. | Sign in again. If you did not request it, tell your administrator immediately. |
Scanning and verification
Section titled “Scanning and verification”| Symptom | Likely cause | Resolution |
|---|---|---|
| You are not allowed to verify this code type | The active profile does not match the code’s tier. | Switch profile (Switching the active profile). The item is not necessarily suspect. |
| Select a verifier first | No profile is active on the device. | Open Verifiers and select one. |
| Camera shows nothing, or is refused | Camera permission denied, or another app holds the camera. | Grant camera access in the device settings; close other camera apps; use manual entry meanwhile. |
| The QR will not read | Print too small, poor contrast, glare, or a damaged label. | Improve lighting, hold steady at 10–15 cm, or type the printed code instead. |
| Stuck on Enable location | The profile requires a position and none is available. | Enable location, allow the permission, and move where the sky is visible (When location is required). |
| Everything times out | No connectivity, or the device cannot reach the server. | Verification always needs a connection. Check the network; on a private installation confirm the device is on the right one. |
| Verdict says withdrawn for stock you believe is fine | The brand, product, batch, issuance or the owner’s account has been archived. | Ask the brand — the withdrawal is deliberate (Archiving — nothing is ever deleted). |
Dashboard
Section titled “Dashboard”| Symptom | Likely cause | Resolution |
|---|---|---|
| Records are missing | The status filter is on Active, or (administrators) the owner filter is on the wrong owner. | Switch the status filter to see archived records; check the owner selector (The owner filter). |
| Times look wrong | No timezone set on your profile. | Set it in Profile (Name and timezone). |
| Quantity must be between 1 and 1000 | Too many codes requested at once. | Split the run into several issuances. |
| Please upload an image file / attachments must be images or PDFs | Unsupported file type. | Convert to PNG, JPEG or PDF, under 8 MB. |
| Upload fails silently on a large file | The file exceeds 8 MB. | Compress or resize it. |
| No print template available | No label template is configured on the platform. | Ask an administrator (Platform configuration). |
| Object storage is not configured | Server-side storage is unavailable, so files and documents cannot be saved. | This is an installation problem — contact whoever operates your AuthPlus server. |
| The map is empty | No operations match the filters, or none carry a position. | Widen the date range and clear filters; remember approximate locations depend on the network. |
| A page briefly shows a generic error | Transient server or connectivity problem. | Use the retry action. If it persists, note the time and contact support. |
Frequently asked questions
Using AuthPlus
Section titled “Using AuthPlus”- Do customers need an account to verify a product?
- No. The verification app works with no account and no registration, in the mobile app or a browser.
- Does verification work without an internet connection?
- No. Authenticity is decided by the server, so a connection is always required.
- Can I verify a product without the mobile app?
- Yes — open the AuthPlus website and choose the verification area. Everything except precise location works the same way.
- What if the QR code is damaged?
- Type the code printed beside it. Codes deliberately avoid the characters most often confused.
- Someone scanned my product before me. Is it fake?
- Not necessarily — a batch is normally checked by the factory, the distributor and the shop. What matters is the pattern: many checks, in distant places, in a short time.
Codes and printing
Section titled “Codes and printing”- How many codes can I issue at once?
- Up to 1000 per issuance. Larger runs are split into several issuances, which also gives finer recall control.
- Can I reuse or re-issue a code?
- No. Every code is unique and permanent. Issue new codes instead.
- Can I change a product's name after codes are printed?
- Yes — verdict screens show the current details. What is printed on the physical label does not change, so keep the two consistent.
- What size should the printed QR be?
- Test before the full run. Print one sheet at the final size, on the final material, and scan it with an ordinary phone (Labels & exports).
- Can I stop a single code without affecting the batch?
- Yes. Archive that one code. Archiving the issuance, item, product or brand affects everything beneath it.
Accounts and access
Section titled “Accounts and access”- I forgot my password.
- Use Forgot password, or sign in with a one-time email code (Signing in).
- Can an administrator see my password?
- No. Passwords are stored only as an irreversible hash. An administrator can set a new one for an account they create, but cannot read an existing one.
- Can two people share one account?
- Technically yes, but do not: the audit trail attributes every action to the account, so sharing destroys accountability.
- What happens to my products if my account is archived?
- They stop verifying — every code you own returns withdrawn until the account is restored (Archiving an account).
- How do I get the Admin role?
- Another administrator must grant it. It cannot be requested from the interface.
Data and privacy
Section titled “Data and privacy”- Is my document uploaded when I verify a file?
- No. The fingerprint is computed on your own device and only that value is sent. Checking a link is different: there the server downloads the file to hash it.
- Can I delete a record?
- Records are archived, not deleted, so the audit trail stays intact. Archived records stop verifying and can be restored.
- Who can see where a scan happened?
- The owner of the scanned code, and administrators. Verifiers see their own history.
- Will I be notified if one of my codes is abused?
- Not by email or push — a warning appears in the dashboard and the sidebar badge (Notifications).
Glossary
- Archive
- To withdraw a record without deleting it. Archived records stop verifying and can be restored (Archiving — nothing is ever deleted).
- Asset
- A unique valuable registered individually and carrying a signed ownership certificate.
- Authenticity code (code)
- The unique string, printed as text and as a QR symbol, that identifies one protected unit.
- Batch
- An item under a product: one production run, to which codes are attached.
- Brand
- The top of the protection chain; the name shown to anyone verifying.
- Code type
- The tier of a code — Public, Reseller or Control — which decides who may verify it.
- Content
- A certified file: a document, certificate or media item bound to a fingerprint of its contents.
- Custody / holder
- Which verifier profile currently holds an item in the field. Moved by a transfer in the app (Transfers & custody).
- Fingerprint
- A value computed from a file's exact contents. If the file changes, the fingerprint no longer matches.
- Issuance
- One act of minting codes for an item, and the unit at which codes are printed and withdrawn.
- Item
- A concrete unit: a batch of a product, one individual valuable, or one document entry.
- Operation
- One recorded verification or transfer — a line in the audit trail.
- Over-verified
- A code checked more times than its ceiling allows; the principal automated counterfeit signal.
- Owner
- The account a record belongs to, and the boundary of who can see it.
- Owner filter
- The administrator control that chooses whose data every screen shows (The owner filter).
- Ownership transfer
- Moving a code from one AuthPlus account to another, in the dashboard. Distinct from custody.
- Product
- A manufactured good produced in quantity, organised into batches.
- Subject
- The generic term for a product, an asset category or a content category.
- Superadministrator
- The platform operator's account, which configures code types, templates and verifier types.
- Verification ceiling
- The number of scans a code may receive before a warning is raised (Your verification ceilings).
- Verifier
- The identity under which a scan is recorded — a device profile, not a dashboard account.
- Verifier type
- The template governing a verifier's behaviour: which codes it may check, whether it self-provisions, whether it needs location.
- Verification badge
- The green check displayed beside a brand whose identity AuthPlus has confirmed (Brand verification).
- Warning
- An automatic alert on suspicious activity, awaiting a human decision (Warnings, Moderation).
Support
Getting help, and what to include so that help is fast.
Before you contact anyone
Section titled “Before you contact anyone”- Check §38 Troubleshooting — the majority of reports match an entry there.
- Reproduce the problem once more and note the exact wording of any message.
- Confirm whether it affects one record, one device, or everyone.
What to include
Section titled “What to include”| Detail | Why it matters |
|---|---|
| The exact message | Distinguishes between a dozen similar-looking causes. |
| Date, time and your timezone | Lets the team find the corresponding record. |
| The code, brand or record involved | Identifies exactly what was affected. |
| The account and role you were using | Many behaviours are role-dependent. |
| Web or mobile app, and the device | Camera, location and storage issues are platform-specific. |
| The version at the bottom of the sidebar | Confirms which release you are running. |
| A screenshot | Faster than any description. |
Who to contact
Section titled “Who to contact”- Questions about your own catalogue, codes or account — your organisation’s AuthPlus administrator, who can see your records and act on them directly.
- Everything else — platform faults, installation and configuration questions, and suspected security problems — write to contact@authenticity-plus.com.