A certificate delivered as a PDF — even with a scanned signature and a seal — has a structural problem: it is an editable file. Whoever receives it cannot tell the original from a doctored copy, and the only way to check is to email or call the issuer. In international professional mobility, where a certificate crosses three countries and four agencies, that means almost nobody checks almost anything.

Verifiable credentials flip the burden: validity doesn't live in the file. It lives at the source.

A PDF is a photo, not proof

Altering a PDF with an editor takes minutes: crop a signature, change a name, adjust a date. Verifying it through the traditional channel — an email to the issuing body — takes days or weeks, when they answer at all. The asymmetry is total: forging is cheap, checking is expensive. That is why paper and PDFs circulate on faith.

What a verifiable credential is

When a case file is completed, Booka issues a certificate with a unique code and a QR. The document can be printed and passed around like any PDF — but the claim of validity isn't on the paper: it's on a public verification page that answers against Booka's registry in real time.

The principle: validity is confirmed by the source, not by a file anyone can edit.

How long does your credentialing take today?

Measure your corridor's timelines with a pilot before committing volume.

How verification works: seconds, no account

  1. 1

    Open the public verification page (or scan the QR on the certificate).

  2. 2

    Enter the code.

  3. 3

    See the result in seconds: issuer, holder, scope, and status of the certificate.

No account, no login, no phone calls. A government official, a hospital, or the professional themselves can run the same check with the same gesture.

Tamper-proof by design

  • The file is not the proof. Editing the PDF changes nothing: the public lookup answers from the registry, not from the paper.
  • Rate limiting on the public endpoint. Brute-force enumeration of codes is cut off at the infrastructure layer.
  • Opaque codes, zero personal data in the URL. The code encodes nothing about the holder; no personal data ever travels in a query string.

What it confirms — and what it doesn't

The public check confirms that the certificate exists, who issued it, whom it covers, and its current status. It does not replace a regulator's decision: the administrative effect of each procedure is set by the competent authority of the receiving country.

The person behind the certificate

A certificate is worth only as much as the identity it covers. Booka's Trust Agent cross-checks background records, passport identity — mathematically validated via MRZ — and professional standing, and unifies everything under one robust identity key: a professional never fragments into two files over a typo. And because a credential can stop being valid after it is issued, continuous license and sanctions monitoring closes the loop. More detail at Trust Agent.

The next level: eIDAS seals

For documents digitally signed by European universities and ministries, cryptographic validation of eIDAS seals — via the European Commission's DSS framework — is the strongest possible authenticity signal on a document. Booka has it evaluated and ready to activate. The regulatory context is covered in the European Professional Card and eIDAS2.

Conclusion

As long as the certificate is a file, trust is an opinion. A verifiable credential turns the check into an act of seconds, public and frictionless — and moves fraud from the easy terrain (editing a PDF) to the impossible one (altering the source's registry). The buyer doesn't have to believe. They can verify.