Certora
Certificates with a unique code and a public verify page, delivered to recipients by private link.
For training providers, course creators, event organizers and HR teams. Often replaces Certifier, Sertifier or Accredible.
Single license $79 · Extended license $179 · paid once, yours for good
What it does
Anyone can confirm a certificate by its code: recipient, course, issuer, issue date and validity. A miss is a plain not-found.
A template and a recipient list give one certificate each, with a unique code. Tick more templates and each person gets a set.
Each recipient gets a private link to their own PDF, no account needed. Batches send in slices and nothing sends twice.
Recipients add the certification to LinkedIn from the verify page or their email. Name, dates, code and your verify link are filled in.
Switch on hosted Open Badges 2.0. Each certificate's badge data lives on your server, with the recipient's email hashed.
Every lookup on your verify page is counted, by certificate and template. Near-misses on a real code are flagged.
A recipient types their email and gets a link to everything you issued them. No account.
Upload a JPEG or plain PNG and it is embedded in the PDF as it is, never stretched.
Give a template a validity period and each certificate carries an expiry date. The verify page shows expired as expired.
Title, body, recipient, course, date and issuer tokens, a signatory line and orientation.
Search every certificate, revoke or reinstate, and export the register as a formula-safe CSV.
Each certificate renders as a PDF with no external libraries or services. It carries a QR code of its verify link once your verify address is set.
Also: CSV recipient import, expiring-soon counts on the dashboard, a phone install from the browser, and an API and MCP endpoint for your own agent.
Self-hosted without the assembly
The other answer to “self-hosted” is a repository: clone it, read the compose file, provision a database, wire up mail, then keep it patched yourself. That is a fair answer when running infrastructure is already your job, and we would rather say so than pretend otherwise. This is the other kind. It is bought once at $79.00, the full PHP source is in the download, and the web installer finishes on ordinary shared hosting in about two minutes. No Composer, no Node, no build step, nothing to compile, and nothing that phones home.
What Certora deliberately doesn’t do.
- Not a PKI/digital-signature system — verification is a database lookup on your server: the code resolves to the record you issued, or it does not. Provenance, not cryptography.
- Email goes through your own SMTP; certificates are delivered as a private link, never as an attachment, and delivery is off until you switch it on.
- A seal or logo on the certificate must be a JPEG or a plain 8-bit PNG (no transparency, interlacing or palette) — the PDF is written without an imaging library on purpose.
- Single-tenant: one issuing organization per installation.
What renting costs instead
1 month of Certifier costs what Certora costs once.
Read Sep 24, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? Certifier alternative · Sertifier alternative · Accredible alternative
Release history
For Certora, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Certora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
3.3 lets one run issue a set. What’s new in 3.3 →
3.2 took each certificate beyond the PDF.
The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…
Six MCP tools let an agent list templates, read the register, issue a batch, verify a code and pull the expiry report — with the write tool on the same code path as…
The owner layer every Ownware app carries.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- LICENSE.txt
- QUICKSTART.txt
- README.md
- assets/
- bin/
- config.sample.php
- controllers/
- deploy/
- index.php
- install/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Qr.php: a real module, the first 24 of 441 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php /** * Qr.php — a QR Code encoder, byte mode, error-correction level M, versions 1..10. * * CERTORA (3.1.4): copied unchanged from Assetora, where it was written and proved for * printed asset labels. Here it puts the certificate's /verify link on the PDF as a QR code, so an * employer scans instead of typing a 12-character code. tests/qr_check.php (copied with it) reads * every symbol back with an independent decoder and checks the Reed-Solomon parity. The notes * below are Assetora's and still describe the encoder exactly. * * WHY THIS EXISTS AT ALL. The 3.0 signature feature is a printable label sheet: one QR per asset * that opens that asset's page. A label sheet that does not scan is worse than no label sheet — * somebody sticks four hundred of them onto four hundred machines before anyone finds out. So the * encoder is written from ISO/IEC 18004 rather than approximated, and the suite checks it against * an independent reference implementation, matrix for matrix, not by eye. * * WHY NOT A SERVICE OR A LIBRARY. A QR image endpoint would send the customer's asset URLs to a * third party on every label print, and this product is sold on the promise that it talks to * nobody. There is no Composer dependency either: the whole apps is drop-in-and-run PHP. * * SCOPE, deliberately. Byte mode only (a URL is bytes), level M (~15% recovery — the right trade * for a label that will be scuffed but is not on a foundry floor), versions 1..10, which carries a * 213-byte URL (version 10-M holds 216 data codewords, less the 4-bit mode indicator and the * 16-bit character count that versions 10 and up use). Beyond that encode() refuses loudly rather
Runs on: 2-minute web installer, plain PHP 8.1+ with MySQL (or SQLite for a trial), no Composer or build step — Docker image included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- certora <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Is the verification cryptographic?
Can verification codes collide?
What stops someone brute-forcing the verify page?
Can I revoke a certificate?
Do certificates expire?
Will it run on shared hosting?
Can it email certificates to recipients?
Is Certora a subscription?
What exactly do I get for the money?
Can I get the certificate records out?
Covered in these guides
More about Certora
Self-hosted certificate verification for training providers and awarding bodies: every certificate carries a unique code an employer can check on a verify page you host yourself.
The problem it solves
If you want a self-hosted certificate generator with verification — issue certificates in bulk, and give employers a verify page you host rather than a credential platform that bills per certificate — that is exactly what Certora is: $79 one-time, full PHP source, unique verify codes, expiry tracking, and shared hosting is enough.
Training providers, course creators, event organizers, and HR teams all hit the same wall: fifty (or five hundred) people finish, and each needs a certificate — plus a way for an employer to check it's real, years later. Doing it by hand means mail-merging documents one at a time and answering verification emails forever. Certificate SaaS charges per certificate, per recipient or per month, and the verify page lives on someone else's domain, on their terms.
- One PDF per recipient, generated by hand, every cohort
- "Can you confirm this certificate?" emails, indefinitely
- A verification URL on someone else's domain, on their terms
Every feature
- Certificates reach the people who earned them. Each recipient gets a private link to their own PDF — no account, no login, the token is the credential. Batches send in bounded slices (a cohort of 500 can never time out halfway), every skip states its reason, and nothing sends twice.
- A real seal on the certificate. Upload a JPEG or plain PNG and it is embedded into the PDF byte-for-byte — no imaging library, no re-encoding — centered, scaled to fit, never stretched. Certificates without a seal stay byte-identical to before.
- Certificate templates. Design templates with title, body, merge tokens ({recipient}, {course}, {date}, {issuer}, {code}), signatory line, orientation, and optional logo/seal text.
- CSV recipient import. Import recipients from CSV with columns matched by header name, or add them manually.
- One-click batch generation. Template × recipient list → one certificate each, with a random database-unique verification code and issue date — collision-free even at a 1,000-certificate batch.
- Dependency-free PDFs. Each certificate renders as a PDF with no external libraries or services: positioned text in a monospaced typeface (Courier), a double border, a centered layout and, when your public verify address is set, a QR code of its verify link.
- Public verify page. Anyone can confirm a certificate at /verify/{code}: recipient, course, issuer, issue date, and validity — with a honeypot, per-IP rate limiting, and a plain not-found on a miss.
- Expiry tracking. Give a template a validity period and every certificate issued from it carries an expiry date (snapshot at issue, month-end clamped). The public verify page shows expired certificates as expired, the register and CSV carry the expiry, and the dashboard counts expiring-soon and expired.
- Issued register. Search every issued certificate, revoke or reinstate, and export the register as a formula-injection-hardened CSV.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- Add to LinkedIn in one click. Recipients add the certification to their LinkedIn profile from the verify page or their email, with name, dates, code and your verify link filled in.
- See that your certificates are checked. Every lookup on your verify page is counted: by certificate, by template, and the codes that matched nothing, with near-misses on a real code flagged.
- Open Badges on your own domain. Switch on hosted Open Badges 2.0: each certificate gets a badge whose data lives on your server, with the recipient's email hashed.
- Every certificate, one private page. A recipient types their email and gets a link to everything you issued them. No account.
- A set of certificates in one run. Tick more than one template and each person gets one certificate from each, for example a course completion and a CPD record, each with its own code and verify page (and its own badge, with badges on).
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Certora, 4.0.1 fixes an installer that had lost its styling and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Certora, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Certora, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Certora to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Certora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.3: a set of certificates in one run. 3.3 lets one run issue a set. Tick more than one template and each person gets one certificate from each, for example a course completion and a CPD record, each with its own code and verify page.
- Own It 3.2: a certificate that travels. 3.2 took each certificate beyond the PDF. Recipients add it to LinkedIn in one click, hosted Open Badges 2.0 can live on your own domain, and a recipient gets one private page of everything you issued them. You also see that your certificates are checked: every lookup on your verify page is counted, with near-misses on a real code flagged.
- Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
- Own It 3.0: works for your AI, not just for you. Six MCP tools let an agent list templates, read the register, issue a batch, verify a code and pull the expiry report — with the write tool on the same code path as the Generate screen, so an agent cannot mint a certificate the UI would refuse.
- Own It 2.0: API, 2FA, backups, dark mode. The owner layer every Ownware app carries. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Compliance software · School & training-provider software · Driving-school software