Every document eSerbisyo generates carries a scannable QR code. Here is what it does, how verification works, why it stops tampering, and where its honest limits are.
Think of the QR code like a barcode on a product in a store. A barcode doesn’t contain the product’s entire manufacturing history; it points to a record. The QR code on an eSerbisyo document works the same way. It encodes a unique web address that links back to a single record in the barangay’s database.
When someone scans the code (with a phone camera, a QR reader app, or even by typing the URL into a browser), the system looks up that record and displays the document’s details: what type of document it is, who it was issued to, when it was generated, and whether it is still valid. The PDF itself is not the proof of authenticity; the database is.
The verification flow is deliberately simple so that anyone (a school registrar, an HR officer, a government clerk) can do it without training:
The QR verification mechanism addresses the three main ways a paper document can be faked or altered:
QR verification is designed for the people who receive documents and need to decide whether to trust them:
Verification is available in two ways. The verifier can scan the QR code with any smartphone camera or QR reader, which opens the verification page directly. Alternatively, they can type the URL printed beneath the QR code into any web browser. Either way, the same verification page loads and shows the document’s status.
What the verifier sees is simple and unambiguous: the document type, the recipient’s partial name, the issuance date, and a clear status indicator: verified, revoked, or not found.
QR verification is powerful but not magical. It has one clear boundary that is worth stating plainly:
The system cannot prevent someone from creating a brand-new fake document from scratch, complete with a fabricated QR code that points to a made-up URL or to a page they control. What itdoes make trivially easy is catching that fake. A verifier who scans the QR will either land on a legitimate verification page (in which case the details on the page won’t match the fake document) or land on a page that clearly isn’t the barangay’s system.
In other words, QR verification doesn’t make forgery impossible; it makes forgery hard to pass off andeasy to detect. A tampered copy is caught immediately. A completely fabricated document requires fabricating the QR verification endpoint too, which is significantly harder and still fails under scrutiny.
Under the hood, the QR code generation is straightforward:
Because the request ID is generated server-side and is sequential or UUID-based, it cannot be guessed or predicted by an end user. The QR code is a convenience layer on top of a database lookup; the security comes from the database record, not from the code itself.