SyncNexaSyncNexa
Docs
v1.0 (Latest)

QR Code & In-Person Verification

v1.0

Step-by-step guide for scanning dynamic QR codes, handling rotating time-based tokens, and preventing screenshot fraud in physical environments.

Last updated: August 2026

Physical verification with SyncNexa provides airtight protection against counterfeit student cards and shared discount screenshots using cryptographically rotating dynamic QR codes.

How Dynamic QR Codes Work

Static QR codes (such as a printed barcode or static image) are vulnerable to screenshot sharing. SyncID QR codes are dynamic and ephemeral: every QR code generated by the student's device contains an encrypted challenge payload that expires within 30 seconds.

The In-Person Scanning Process

1

1. Student Opens SyncID App

The student opens their SyncID mobile app and selects the credential they wish to present (e.g. *Student Enrollment Proof*). The app generates a dynamic rotating QR code.

2

2. Verifier Scans the QR Code

The store cashier or venue staff member points the Verification Portal camera scanner at the student's screen.

3

3. Instant Proof Validation

The Verification Portal sends the encrypted payload to the SyncNexa Verification Service, which verifies the institutional signature and zero-knowledge proof.

4

4. Instant Visual & Audio Feedback

The portal displays an animated green checkmark with the verified university name and emits a confirmation chime for hands-free cashier workflows.

Anti-Screenshot & Anti-Fraud Protection

One-Time Nonce & Expiration
If a student takes a screenshot of their QR code and sends it to a friend, the QR code will have already expired before the friend can present it at the register. Replay attempts are instantly rejected by the verification gateway.

Network Fault Tolerance

In environments with intermittent connectivity (e.g., underground subway transit, outdoor music festivals), the Verification Portal caches trusted university public keys locally in browser IndexedDB, allowing offline cryptographic validation of time-stamped signatures.

Was this page helpful?