Digital credentials

The certificate outlives the institute. Design for that

A certificate is issued in an afternoon and needed for forty years, while the institute behind it renames, rebrands, changes software or closes. Here are the three ways certificates die, the six properties that make permanence a design requirement rather than a promise, and what an issuer should do on the day of issue.

A verification record in Certifada that keeps answering long after the issuing institute has changed

A certificate is issued in an afternoon and needed for forty years. That mismatch is the whole problem.

The institute that issued it will change its name, move buildings, replace its website twice, switch software three times, and quite possibly close. The graduate will need the certificate at the worst possible moments: a visa application in a country that checks, a job abroad, a licence renewal, a promotion board. Those moments arrive ten, twenty, thirty years after the course, long after anyone at the institute remembers the cohort, and sometimes long after there is an institute at all.

Almost nothing about how certificates are issued today is designed for that gap. This article is about designing for it.

The two lifespans do not match

Training centres, language institutes, bootcamps and professional academies are businesses, and businesses have lifespans. Many are excellent for a decade and then merge, rebrand, change owners or wind down. Nothing wrong with that. But a credential does not expire when its issuer does. The claim "this person completed this programme in 2026" stays true forever, and the people who need to check it keep arriving.

Meanwhile the things institutes rely on to prove their certificates are all short-lived:

  • The domain lapses when someone forgets to renew it, or when the new owners drop the old brand. Every verification page that lived on it goes with it, and a squatter may take the name.
  • The email address on the certificate bounces the day the mailbox is closed.
  • The registrar's spreadsheet lives on a laptop that was retired, or in a drive nobody can open.
  • The software was on a subscription, and a subscription ends.

A graduate holding a 2026 certificate in 2041 needs none of those to still exist. Today, they need all of them.

The three ways certificates die

The institute-hosted verification page. A "verify" page on the institute's own website is the most common attempt at permanence, and the most fragile. It dies with the domain, it changes with every website redesign, and it is only as trustworthy as the institute's current web administrator. It also cannot be checked by anyone who does not already know the institute's real address.

The PDF. The file survives, because files are easy to keep. But a file proves nothing on its own, and as we set out in AI can forge a certificate in ten seconds, it now proves less every year. A PDF with no record behind it is a photo of a certificate.

The platform with a subscription. This is the modern failure, and the quiet one. Many credentialing tools tie verification to the issuer's account: the pages work while the invoices are paid and go dark, or get deleted after a grace period, when they stop. The graduate did nothing wrong and never had a say. Their proof was rented on their behalf, and the lease ran out.

None of these is malicious. They are what you get when permanence is treated as a nice-to-have instead of a requirement.

Permanence is a design requirement

If a certificate must outlive its issuer, then a few properties stop being features and become the definition of doing the job.

  1. The record is held independently. Not on the issuer's domain, not in the issuer's files, but on a platform whose purpose is to hold records, at an address that does not change when the institute does. The QR code on the certificate points at that record, never at the institute's own site.
  2. Verification does not depend on the issuer's account. The public page is served from the record, not from the issuer's session, plan or payment status. A lapsed subscription changes what the issuer can do next; it must not change what a graduate can prove.
  3. The record carries enough to stand alone. The issuer's identity as it was verified at the time, the programme name, the criteria and skills, the issue and expiry dates, and the status. A verifier in 2041 should not need to phone anyone.
  4. History is preserved, including revocation. A revoked credential shows as revoked, with its dates, rather than disappearing. A record that can be silently edited or deleted is not a record.
  5. It exists in an open format. An Open Badge with a hosted assertion can be exported, imported into other systems and verified by any compliant tool. The graduate is never locked to one platform's interface.
  6. It is free to check, without an account. If verification costs the verifier money or a sign-up, it will be skipped, and a proof nobody checks is a picture.

What "free forever" has to mean structurally

Promises are cheap. The structure behind them is what matters, so here is Certifada's:

  • Verification pages are read-only and served from the credential record, separated from the issuing account entirely. A change to the account does not touch the page. This is the design described in why verification is free forever.
  • Serving a verification costs a fraction of issuing one, so there is no reason to meter it and no incentive to switch it off.
  • Credentials issued while a workspace was active stay verifiable after the subscription ends.
  • Every badge is a valid Open Badges 2.0 assertion, hosted at a permanent address, so a graduate can take it elsewhere at any time.
  • Issuer identity verification is recorded when it happens, so a credential issued by a verified institute still shows that fact years later.

That is what it means for a certificate to outlive an institute: not a promise in a contract, but a page that keeps answering.

What an issuer should do now

Most of the work happens on the day of issue, because that is the only day the institute is guaranteed to exist.

  • Issue through a platform that holds the record. Every credential you issue as a PDF only, or with a QR code pointing at your own website, will need rescuing later, and later may not come.
  • Complete issuer verification while you can. Your identity claim is captured while you are around to prove it. It is much harder to verify an institute that no longer exists.
  • Print the platform's verification address on the paper, not your own domain. Your domain is the thing most likely to disappear.
  • Write the programme and the criteria into the credential. In twenty years nobody will remember what "Level 3" meant. The record should say.
  • Tell graduates the link is theirs. It works without you, and they should know that.
  • Re-issue past cohorts. Old certificates can be issued as verifiable credentials from a spreadsheet. It is the only way to give alumni proof that does not depend on you staying open.

The graduate's view

From the graduate's side the test is simple. Take the certificate you received, imagine the institute has vanished, and ask: can a stranger still confirm this in a minute? If the answer depends on a website, an email address or a subscription that belongs to someone else, the certificate was never really yours. If it depends on a record that stands on its own, it was.

Issue certificates that pass that test, and the mismatch between an afternoon and forty years stops being a problem.

  • #Digital certificates
  • #Open Badges
  • #Verification
Sharein𝕏fchat

About the author

Certifada Team · Editorial team

The people who build Certifada, writing about digital credentials, verification and what we learn from issuers.

More from Certifada Team