Help · How it works
How QR code attendance works
A screen shows a code that changes every thirty seconds, people scan it with the camera they already have, and the server decides what counts.
A screen by the door shows a QR code. People point a phone camera at it, a page opens in the browser, and one button records the check-in. The code changes every thirty seconds, and the server — not the phone — decides whether a scan counts.
That last part is what separates a QR attendance system from a printed sign.
Why the code changes
A code that never changes is a photograph. Somebody takes a picture on Monday and checks in from the car park for the rest of the year.
Ours is generated fresh for each window, signed by the server, and carries the window it belongs to. A scan from an old window is refused. You can watch this in the demo: there is a control that hands you a code from a minute ago, and it is turned away.
A photographed code still works for exactly as long as the window plus its grace period — thirty seconds plus two minutes by default, both adjustable per location. That is a real limit rather than a loophole: some tolerance is necessary, because a code that expires the instant it leaves the screen fails honest people whose phone was slow.
What the screen can be
Any device with a browser and a modern camera-capable phone at the other end: a spare tablet, an old phone, a TV, a laptop nobody uses. It needs power, a network and a browser pointed at its display page. There is no terminal to buy, no badge reader, and no per-device licence.
If the screen stops reporting, we say so — Live shows that check-ins are impossible at that location, so an empty list there does not read as an empty building.
What happens between the scan and the record
- The camera opens the link, which carries the signed code
- The person signs in with the Google account they already have, once, on that phone
- The server checks the signature, the window, and whichever checks that location enforces
- One button — In or Out, decided by what they did last
- The row appears in the report, on that location’s business day
Nothing runs in the background at any point, and nothing is recorded between check-ins.
Why the server decides
Every scan is checked the moment it happens: the signature, the window, and whichever checks that location enforces. The record is confirmed at the door, so every row is something the server saw at the time it happened — not something a phone reported afterwards.
The time on the row is ours, in UTC. A check-in is stamped by our server, and the phone’s clock is never consulted — so a device with its date wound back records exactly the same minute as one without.
See how a check-in actually works for the mechanics, or set one up — it takes about five minutes and ends with you scanning your own screen.
Still stuck? Try the demo — most questions here are quicker to answer by pressing the thing than by reading about it.