Docs
Visitors

Signed passes and offline checks

Every pass carries a code signed with your organisation's own key, so a kiosk or guard can check it with no network. How it works, and how to replace the key.

Early access· P4For owners, admins, receptionists and guards

Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.

Dumsor doesn't wait for visitors to finish arriving. So that a gate keeps working when the network doesn't, the QR code on every pass, on every plan, carries a code digitally signed with your organisation's own pass key. A kiosk or guard device can check that code on its own: that the pass is genuine and unaltered, and that it admits now, at this gate.

What a signed pass holds

In the codeNot in the code
The pass's own code (the same one its link carries)The visitor's name, phone number or email
When it starts admitting, and when it stopsWho the host is, or why they're visiting
Its daily hours, if it has themAnything about your organisation's other visits
Whether it's single use
The gates it admits at, if it's limited to some

and the signature over all of it. Changing anything in the code breaks the signature, so a pass with its dates or gates edited is refused. Your organisation isn't written in the code either: a device checks a pass against its own organisation's keys, so a pass from another organisation never passes.

See Multi-day passes and pass rules for days, hours, single use and gates.

Passes that aren't signed

  • A pass waiting for its host's approval isn't signed: its QR code holds the pass's link instead, so nobody can be let in offline before someone has said yes. Once the host approves, the pass is signed the next time the visitor opens it.
  • A walk-in's visit page (after self check-in) is for the visit already under way, so it isn't signed.

Unsigned codes still work: reception can scan them, and kiosks check them online or against the expected visits they synced.

How devices check a pass

Kiosks and guard devices (Kiosk app: iPad and iPhone in P5, Android in P6) keep your organisation's public pass keys and a list of the passes at their site that stopped working early: cancelled, declined or missed visits, and passes replaced when one was sent again. When someone scans a pass, the device checks:

  1. the signature, with your organisation's key;
  2. that the pass isn't on the list of passes that stopped early;
  3. its days, daily hours and gates, against the device's own clock and gate;
  4. for a single-use pass, the device's own entries.

A pass that fails is refused with a polite message to see reception, which can let them in anyway if that's right. A pass cancelled after the device lost its connection can't be on its list yet: the device accepts it, and the visit is flagged for reception to review when the device syncs. See Offline mode.

In the Console, Scan a pass reads signed codes and links alike. See Front desk.

Your pass key

Each organisation has its own pass key, made the first time a pass is signed. Agoo stores only its public half, which devices use to check passes; the private half is never stored anywhere and can't be downloaded.

Replace the key

Owners and Admins can replace the key in Console → Settings → Security, under the pass key, by selecting Rotate key. Do it if you believe your key has been misused, or as part of your own security routine.

  • The old key stops being used at once, and the change is recorded in the audit trail.
  • Each pass is signed with the new key the next time it's opened. Passes shown before then carry the old key's signature: devices check those online, or against their synced list of expected visits, until the visitor opens their pass again.
  • Nothing needs reprinting or resending.

For developers

Treat a pass's QR code as opaque: its format is for Agoo's own kiosk and guard apps. To work with a visit's pass, use the visit's pass object in the API.

On this page