Issue a pass, print or send it, and check it at the door on any phone. A screenshot, a forward and a photo of somebody else’s ticket all redeem exactly as many times as the original: once.
Issue your first pass
An ordinary QR code opens a page. It has no memory of who has used it, so a ticket built from one can be screenshotted, forwarded and used by ten people. The code itself carries no authority.
A pass is different: it is one admission, issued against a code, and the authority lives on the server. The holder’s QR encodes an address that identifies the pass; whether that pass may be used is decided when it is presented, not when it was printed. So a forwarded screenshot is not a second ticket — it is a second attempt to spend the same one.
The hard case in ticketing is not fraud, it is timing. Two staff scan copies of the same ticket at two entrances within the same second. If each one reads "unused" before either writes "used", both let someone in.
Redemption closes that window: the check and the increment happen together, against a locked record, so one of the two scans wins and the other is told the pass has already been used. That is the whole reason the feature exists, and it is why looking at a pass and spending a pass are separate operations — a holder opening their own ticket to show a doorman must never use it up.
Every attempt is recorded, refusals included. "The door said it was already used" is a dispute somebody has to settle later, and it is impossible to settle if only successes were kept. The log shows what was presented, when, and what the answer was.
Staff can only validate passes belonging to their own account, and a pass from another account is reported as not recognised rather than as forbidden — confirming that somebody else’s ticket exists is itself a leak.
What the feature actually does, part by part.
One admission, a single-use voucher, or a card worth a set number of visits that counts down.
Two doors scanning the same ticket in the same second get one yes and one no, never two yeses.
The holder can open their own pass to show it without using it up. Only a staff validation redeems.
Refusals are recorded as well as admissions, because that is the half a dispute turns on.
A web validator screen for staff, and the same decision served to the mobile app through the API.
Print passes on label sheets with the token readable under the code, for when a camera will not focus in the rain.
Anywhere something must be redeemable once and only once.
No technical knowledge required.
Create a QR code for the event or offer, and issue passes against it.
Give each pass a name and, for multi-visit cards, the number of uses it is worth.
Send or print them — printed sheets carry the token in readable characters under the code.
At the door, open the validator on any phone and scan.
The screen says admitted, already used, or expired — and every attempt is written to the log.
Taken from the live plan matrix, so this page and your account always agree.
See the full plan comparison for everything each tier includes.
Straight answers to what usually decides whether this is the right tool for the job.