QR verification and receiver e-sign · How-to guide

Verify an issued Bilty from the QR code

Open the HMAC-protected public verification URL encoded in the issued Bilty QR and compare the permitted shipment fields. The guide follows the Help Centre standard: exact route, prerequisites, ordered steps, verification and operational boundaries.

Audience: Administrators and authorised Bilty operations staffPermission: Relevant Bilty Management capabilityModule v1.0.0
Jump to steps
Where to goIssued Bilty PDF → QR verification
Before you startRequired access: Relevant Bilty Management capability. Work on the correct tenant and record. Use least privilege and review any dependency or protected workflow warning before continuing.

What you’ll accomplish

Open the HMAC-protected public verification URL encoded in the issued Bilty QR and compare the permitted shipment fields. Bilty Management keeps drafts, issued records, public capability links, finance, integration events and audit evidence as connected but separately verifiable records.

How the workflow fits together

Verify issued Bilties publicly, configure permitted fields and collect protected receiver POD signatures. Use the module's current status, permission checks, warnings and linked records to decide the next supported action. Where a downstream invoice, WhatsApp queue item, webhook, PDF, POD record or audit event applies, verify it separately.

Follow these steps

  1. Go to Issued Bilty PDF → QR verification.
  2. Confirm the active tenant, intended Bilty record and your permission before entering or changing data.
  3. Complete the supported workflow: Open the HMAC-protected public verification URL encoded in the issued Bilty QR and compare the permitted shipment fields.
  4. Review the displayed validation, dependent fields and any privacy, finance or integration warning before continuing.
  5. Save, submit or run the action once and wait for the module response.
  6. Reopen the relevant register or record and verify the final status, linked records and audit evidence.

Fields and decisions to review

Verification linkIssued public links are HMAC-protected capability URLs.
Public fieldsOnly explicitly configured non-financial shipment fields are shown.
E-sign tokenSignature submission uses a short-lived link-bound form token.
EvidenceCompleted signatures retain hashes and POD evidence; raw canvas payloads are not audit content.

Record, audit and evidence checks

Reopen the relevant Bilty record or register and confirm its identifier, current status, related parties, timestamps and connected evidence. Check the audit/compliance, payment, public-link, report, API, webhook or WhatsApp evidence that applies to this workflow rather than relying only on a success alert.

How to confirm it worked

Return to Issued Bilty PDF → QR verification or the resulting register and verify that the stored state matches the intended action. For any downstream automation, confirm the downstream record or queue/log entry as a separate completion check.

Technical basis for this guidance

This guide was checked against config/routes.php; controllers/Bilty_public.php; models/Bilty_management_model.php; views/public/verify.php; views/public/sign.php; assets/js/public_esign.js. It documents only behaviour exposed or enforced by the supplied module; internal secrets, raw signature payloads and unsupported future workflow assumptions are intentionally excluded.

Controls, checks and common mistakes

  • Public verification never exposes price/payment data or private contact numbers.
  • Receiver e-sign depends on public verification and fails closed when the dependency is disabled.
  • Do not treat possession of a public capability URL as staff authentication.
Data and workflow safetyConfirm the exact Bilty, authorised audience and final stored status before issuing, publishing a link, recording payment, changing shipment state or sharing a document.