Visitor passes
Issue a pass, or check one at the gate.
Issue a pass
Visitor details and one photo. They leave with a QR code.
Verify at the gate
Scan a pass, take a live photo, compare the face.
About the pass
This deployment
Read from the running server.
- Service
- checking…
What a pass holds
Six fields and a face, sealed and signed.
- Fields
- Visitor ID, name, date of birth, address, phone, email
- Face
- 512 numbers from the face service, 517 bytes — no photograph
- Sealed
- AES-256-GCM, then signed with RSA-2048
- Readable by
- Our readers only. A stranger's scanner sees one long number
- Expiry
- None. Rotating the keys retires every pass at once
How it is built
- The visitor's photo goes to the face service, which returns 512 values describing the face. The photo is discarded.
- Those values are quantised to one byte each, packed with the text fields, gzipped, encrypted, and signed.
- The result is written as a single decimal number, which is the densest thing a QR code can carry.
- At the gate the signature is checked first, so a forged pass is refused before anything is decrypted.