A certificate delivered as a PDF — even with a scanned signature and a seal — has a structural problem: it is an editable file. Whoever receives it cannot tell the original from a doctored copy, and the only way to check is to email or call the issuer. In international professional mobility, where a certificate crosses three countries and four agencies, that means almost nobody checks almost anything.
Verifiable credentials flip the burden: validity doesn't live in the file. It lives at the source.
A PDF is a photo, not proof
Altering a PDF with an editor takes minutes: crop a signature, change a name, adjust a date. Verifying it through the traditional channel — an email to the issuing body — takes days or weeks, when they answer at all. The asymmetry is total: forging is cheap, checking is expensive. That is why paper and PDFs circulate on faith.
What a verifiable credential is
When a case file is completed, Booka issues a certificate with a unique code and a QR. The document can be printed and passed around like any PDF — but the claim of validity isn't on the paper: it's on a public verification page that answers against Booka's registry in real time.
The principle: validity is confirmed by the source, not by a file anyone can edit.
Measure your corridor's timelines with a pilot before committing volume.
How verification works: seconds, no account
- 1
Open the public verification page (or scan the QR on the certificate).
- 2
Enter the code.
- 3
See the result in seconds: issuer, holder, scope, and status of the certificate.
No account, no login, no phone calls. A government official, a hospital, or the professional themselves can run the same check with the same gesture.
Tamper-proof by design
- The file is not the proof. Editing the PDF changes nothing: the public lookup answers from the registry, not from the paper.
- Rate limiting on the public endpoint. Brute-force enumeration of codes is cut off at the infrastructure layer.
- Opaque codes, zero personal data in the URL. The code encodes nothing about the holder; no personal data ever travels in a query string.
What it confirms — and what it doesn't
The public check confirms that the certificate exists, who issued it, whom it covers, and its current status. It does not replace a regulator's decision: the administrative effect of each procedure is set by the competent authority of the receiving country.
The person behind the certificate
A certificate is worth only as much as the identity it covers. Booka's Trust Agent cross-checks background records, passport identity — mathematically validated via MRZ — and professional standing, and unifies everything under one robust identity key: a professional never fragments into two files over a typo. And because a credential can stop being valid after it is issued, continuous license and sanctions monitoring closes the loop. More detail at Trust Agent.
The next level: eIDAS seals
For documents digitally signed by European universities and ministries, cryptographic validation of eIDAS seals — via the European Commission's DSS framework — is the strongest possible authenticity signal on a document. Booka has it evaluated and ready to activate. The regulatory context is covered in the European Professional Card and eIDAS2.
Conclusion
As long as the certificate is a file, trust is an opinion. A verifiable credential turns the check into an act of seconds, public and frictionless — and moves fraud from the easy terrain (editing a PDF) to the impossible one (altering the source's registry). The buyer doesn't have to believe. They can verify.