Help Center · Proof
Issue and share a certificate
Turn a finalized invoice into a signed certificate your client can check at a public link, then share, revoke, or selectively disclose it as needed.
Who this is for
Owners, in practice. Issuing, revoking, and sharing a certificate need the permission that manages certificates; viewing the certificate list needs a separate, lighter permission. By default only the Owner role carries either one. A manager or member can still open Certificates, but sees a message instead of the page's contents unless an owner has granted them one of these permissions.
Before you start
You need a finalized invoice. A certificate can only be issued from one that's been finalized, sent, or paid, never a draft, and it must already have billed time on it. If the invoice is under an active dispute, issuing is refused until that's resolved.
Steps
- Open Certificates.
- Under Issue from an invoice, enter the invoice's id into the Finalized invoice id field.
- Select Issue certificate.
- Find the new entry in the list below. It shows the invoice number and how many claims it carries.
- Select Copy verify link to copy its public link (the button reads Copied! for a moment to confirm), or select Open to view the public page yourself.
- To share only part of the record, select Share redacted. Uncheck any item you don't want to disclose, then select Create redacted share. Use Download bundle JSON to save the shared file, or Open partial verify link to see what your client will see.
- To withdraw a certificate later, select Revoke.
What happens next
Once issued, a certificate's fingerprint is fixed. It can be revoked later, visibly, but never quietly changed or unissued. Revoking flips its status to revoked; the certificate stays in the list, and its public link now shows that it was withdrawn, along with the reason. Creating a redacted share produces a downloadable file and switches the public link to show only the claims you chose. Your client is always told how many were withheld, because the same signature covers the whole record either way.
If it doesn't work
- If issuing fails outright: "Could not issue the certificate."
- If the invoice isn't finalized yet, the server says so directly, for example: *"cannot certify a draft invoice: finalize it first."*
- If the invoice has no billed time on it: *"invoice has no billed time entries to certify."*
- If the invoice is under an active dispute: *"certificate issuance is frozen by an active dispute."*
- No certificates yet: "No certificates yet" / "Issue one from a finalized invoice above."
- If creating a redacted share fails: "Could not create the redacted share."
Related
- Proof Ledger (overview)
- Verify a certificate
- Outcomes (overview)