Help Center · Proof
Verify a certificate
Open the link you were sent to see an independent, up-to-date verdict on a Verified Work Certificate: no account, password, or WorkMonitor login needed.
Who this is for
Clients: anyone who's been sent a certificate link by a WorkMonitor customer to check a piece of billed work. You don't need a WorkMonitor account or any setup to use it. The page works the same whether you're the client, a tribunal, or anyone else the link was shared with.
Steps
- Open the link you were given. There's nothing to sign in to and nowhere on the page to enter a password.
- At the top of the page, note the name shown next to the words Verified Work Certificate. That's who issued it.
- Read the large verdict at the top: Valid (all four checks passed), Revoked (the signature is real, but the issuer withdrew this certificate), Invalid (the contents don't match the signed fingerprint; don't trust the document), Degraded (the issuer's key posture couldn't be fully confirmed right now; nothing is proven false, but verify again shortly), or Not found (no certificate matches the id in your link).
- Open The receipt underneath to see the individual checks behind the verdict: among them, whether the contents match the signed fingerprint, whether the signature really comes from the named issuer, whether a copy of the seal sits in write-once storage, and whether the certificate has been revoked. Select any row to expand a plain-word explanation, plus a copyable line a technically-minded reader could run themselves. Two more rows below the checks give extra, informational context: Worker co-signature, showing whether the worker separately endorsed the certificate (this is never required for it to be valid), and Hardware attestation, showing whether the worker's device could cryptographically vouch for itself (most certificates don't have this yet).
- If only some of the work is shown, look for the note giving the count of claims shown against the total. The signature covers the full total either way, so the issuer can't quietly hide one without you knowing it exists.
- Select Re-check at any time to ask the page to look the certificate up again.
- If you have your own copy of a shared file instead of a link, select Paste or drop a bundle, add it, and select Verify bundle for an independent verdict. Nothing leaves your browser until you press that button.
- Select Download PDF for a printable copy of the same certificate.
What happens next
Nothing on this page changes the certificate. Every check here is read-only. Selecting Re-check simply asks again, so if the issuer revokes the certificate after you first opened the link, re-checking will show that.
If it doesn't work
- No certificate at that id: "No certificate matches this id. That's all we can say. Paste a bundle below if you have one."
- If the page can't reach the verification service at all: "Unable to reach the verification service. Try again shortly."
- Pasting or dropping a bundle: an empty box says "Paste a certificate bundle first (or drop the file)."; text that isn't valid JSON says "That doesn't look like valid JSON. Paste the bundle exactly as it was shared."; a bundle the server can't verify says "Couldn't verify that bundle. Check it's the complete shared artifact."
- If the verdict itself reads Invalid, treat the document as untrustworthy. That's exactly what the page is telling you.
Related
- Certificates
- Proof Ledger (overview)