The regulator owns the number; anyone can check it

Authorities And Verification

Each authority is set up with how it issues — a machine connector or manual capture from its own portal — its environment and its connection state. The API key, username, password and client id are readable by a system administrator only. Every submission is logged with the operation, the certificate and the outcome, with secrets redacted from the payload, and a certificate whose authority has no machine interface goes onto the Awaiting Authority Number worklist instead of being retried against a web page. The QR on a certificate is the authority's own verification link where it returned one, and otherwise a public page keyed on a random token that shows validity, class, period, insurer and registration mark — and nothing else.

The regulator owns the number; anyone can check it
The regulator owns the number; anyone can check it

Every submission, logged

Every submission, logged
Every submission, logged

When, which authority, the operation, the certificate, any error code and whether it succeeded — 97 of them on the demo.

Cancellation by code

Cancellation by code
Cancellation by code

The authority's own codes, which ones need a written note, and whether each was read from the authority's list or a secondary source.

Scan the QR

Certificate and authority number, insurer, class, registration mark and period. No premium, no personal details, no claims history, no policy number.

No confirmation oracle

A code that was never issued and one that has been removed give the same answer, so the page cannot be used to test guesses.

One authority, set up once

One authority, set up once
One authority, set up once

DMVIC recorded as manual capture from the authority's portal, with the scheme, the classes it covers and the environment it runs in.

Was this page helpful?