Signed passes and offline checks
Every pass carries a code signed with your organisation's own key, so a kiosk or guard can check it with no network. How it works, and how to replace the key.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
Dumsor doesn't wait for visitors to finish arriving. So that a gate keeps working when the network doesn't, the QR code on every pass, on every plan, carries a code digitally signed with your organisation's own pass key. A kiosk or guard device can check that code on its own: that the pass is genuine and unaltered, and that it admits now, at this gate.
What a signed pass holds
| In the code | Not in the code |
|---|---|
| The pass's own code (the same one its link carries) | The visitor's name, phone number or email |
| When it starts admitting, and when it stops | Who the host is, or why they're visiting |
| Its daily hours, if it has them | Anything about your organisation's other visits |
| Whether it's single use | |
| The gates it admits at, if it's limited to some |
and the signature over all of it. Changing anything in the code breaks the signature, so a pass with its dates or gates edited is refused. Your organisation isn't written in the code either: a device checks a pass against its own organisation's keys, so a pass from another organisation never passes.
See Multi-day passes and pass rules for days, hours, single use and gates.
Passes that aren't signed
- A pass waiting for its host's approval isn't signed: its QR code holds the pass's link instead, so nobody can be let in offline before someone has said yes. Once the host approves, the pass is signed the next time the visitor opens it.
- A walk-in's visit page (after self check-in) is for the visit already under way, so it isn't signed.
Unsigned codes still work: reception can scan them, and kiosks check them online or against the expected visits they synced.
How devices check a pass
Kiosks and guard devices (Kiosk app: iPad and iPhone in P5, Android in P6) keep your organisation's public pass keys and a list of the passes at their site that stopped working early: cancelled, declined or missed visits, and passes replaced when one was sent again. When someone scans a pass, the device checks:
- the signature, with your organisation's key;
- that the pass isn't on the list of passes that stopped early;
- its days, daily hours and gates, against the device's own clock and gate;
- for a single-use pass, the device's own entries.
A pass that fails is refused with a polite message to see reception, which can let them in anyway if that's right. A pass cancelled after the device lost its connection can't be on its list yet: the device accepts it, and the visit is flagged for reception to review when the device syncs. See Offline mode.
In the Console, Scan a pass reads signed codes and links alike. See Front desk.
Your pass key
Each organisation has its own pass key, made the first time a pass is signed. Agoo stores only its public half, which devices use to check passes; the private half is never stored anywhere and can't be downloaded.
Replace the key
Owners and Admins can replace the key in Console → Settings → Security, under the pass key, by selecting Rotate key. Do it if you believe your key has been misused, or as part of your own security routine.
- The old key stops being used at once, and the change is recorded in the audit trail.
- Each pass is signed with the new key the next time it's opened. Passes shown before then carry the old key's signature: devices check those online, or against their synced list of expected visits, until the visitor opens their pass again.
- Nothing needs reprinting or resending.
For developers
Treat a pass's QR code as opaque: its format is for Agoo's own kiosk and guard apps. To work with a visit's pass, use the visit's pass object in the
API.
Multi-day passes and pass rules
One pass for several days with daily hours and re-entry, and rules for when and where a pass admits, with defaults per visitor type and an override at the desk.
Host approvals
How hosts approve, ask a visitor to wait or decline by push, WhatsApp, SMS link or email, and how delegates and timeouts keep nobody stuck at reception.