How do I verify a digital certificate or credential?
By Bodhih Training Solutions, Bengaluru · UpdatedThe short answer
To verify a digital certificate, open its verification link and confirm the page sits on the issuer’s own domain, not a look-alike. Check the holder’s name, the credential title, the issue date and that its status is valid, not revoked or expired. For an Open Badge, inspect the embedded issuer and criteria data. If anything is missing or doubtful, contact the issuer directly using contact details from its official website.
What are the steps to verify any digital certificate?
These steps work for most online certificates and badges, whoever issued them.
| Step | What to check | Red flag |
|---|---|---|
| 1. Get the link | Ask for the verification link, not a PDF or screenshot | Holder can only send an image |
| 2. Check the domain | The page is on the issuer’s official domain | Misspelt or unrelated domain |
| 3. Match the person | Name matches the candidate and other documents | Different spelling or no name |
| 4. Check the details | Credential title, date and, where shown, what was assessed | Vague title, no date |
| 5. Check status | Valid, not revoked or expired | Revoked or expired notice |
| 6. Inspect badge data | Issuer, criteria and evidence in the Open Badge | Metadata missing or inconsistent |
| 7. Contact the issuer | Use contact details from the official website | Issuer cannot be reached |
How do I verify an Open Badge?
An Open Badge is a digital credential in a published open standard. The badge image carries data about who issued it, to whom, when, and the criteria for earning it. Many badge platforms and validators can read this data.
- Upload the badge image or paste its URL into an Open Badges validator.
- Check the issuer profile URL resolves to the organisation’s real website.
- Read the criteria: what did the holder have to do to earn it?
- Look for evidence links, such as a portfolio or project, if the issuer provides them.
- Check whether the badge has an expiry date or has been revoked.
Why is a PDF certificate not enough?
A PDF or image can be edited in minutes. It proves nothing on its own. A verification link on the issuer’s domain, backed by the issuer’s own records, is much harder to fake, and it reflects the current status: if a credential is revoked, the link shows that, while an old PDF does not.
How do Bodhih credentials verify?
Every Bodhih credential has a verification link that uses an unguessable token: 32 bytes of random data, so links cannot be found by trying numbers in sequence. Anyone with the link can open it and see the credential.
If a credential must be withdrawn, Bodhih revokes it without deleting the record, so the link then shows that it was revoked rather than simply disappearing. Each credential is also issued as an Open Badge 2.0, which the holder can add to a badge wallet or profile.
| Feature | What it means for a verifier |
|---|---|
| Unguessable link (32-byte random token) | Links cannot be guessed or enumerated |
| Revocable without deletion | A withdrawn credential shows as revoked, not missing |
| Open Badge 2.0 | Standard metadata readable by badge tools |
| Credential states movement | Applied AI credentials report change measured, not attendance |
What should HR teams do as standard practice?
If you check certificates regularly during hiring or promotion, make it a routine.
- Ask candidates for verification links, not files.
- Record the date you verified and the status you saw.
- Keep a list of issuers you have confirmed, with their real domains.
- Ask what the credential required: attendance, an exam, assessed work or all three.
- For important roles, ask to see the work behind the credential.
Related reading
Issue credentials people can check
The Bodhih LMS issues verifiable credentials and Open Badges for your own programmes, with revocation and an audit trail.
Questions people ask next
How can I tell if a certificate is fake?
Warning signs include no verification link, a link on a domain that does not belong to the issuer, a name or date that does not match, vague titles and an issuer you cannot contact. When in doubt, contact the issuer directly using details from its official website, not from the certificate.
What is a verifiable credential?
A verifiable credential is a certificate that an outsider can check with the issuer, usually through a link or embedded data, rather than taking a document on trust. It typically shows who issued it, to whom, when and whether it is still valid.
Can a digital certificate be revoked?
Yes, if the issuer supports it. Revocation is used when a credential was issued in error or obtained improperly. Good systems keep the record and mark it revoked, so anyone checking sees that status. Bodhih credentials work this way.
What is Open Badges 2.0?
Open Badges 2.0 is a version of an open standard for digital badges. Each badge carries structured data about the issuer, the recipient, the issue date and the criteria. Because the format is standard, badges can be displayed and checked across many platforms.
Does verifying a certificate prove the person has the skill?
Not on its own. It proves the issuer awarded the credential. How much that says about skill depends on what was assessed. A credential based on attendance says less than one based on proctored exams and assessed work. Ask what was required.
How do I verify a Bodhih certificate?
Ask the holder for their verification link and open it. The page shows the credential and its status. Bodhih links use an unguessable random token, revoked credentials show as revoked, and each credential is also available as an Open Badge 2.0. You can also contact solutions@bodhih.com.
Is a QR code on a certificate a reliable check?
Only if it leads to a verification page on the issuer’s real domain. A QR code is just a link and can point anywhere. Scan it, then apply the same checks: domain, name, details and status.