AVRA product
AVRA Verify: Product Authentication
A serialised code on every unit, and one honest answer when it is scanned.
Your brand
Sample
GENUINE
This code was issued by AVRA, its batch was activated after printing QC, and this scan is within the number of verifications its batch allows.
- Code
- 7XK2 M9PQ 4R
- Brand
- Your brand
- Product
- Your product
Powered by your print partner
01 /Overview
One code per unit. One answer when it is scanned.
Every label your printer produces carries a code that exists exactly once. It is ten characters from an alphabet with no lookalike letters — around 8 × 1014 possibilities — so it cannot be guessed, and it is useless until the batch it belongs to has been activated after the print run passes QC.
A consumer opens the phone camera, points it at the label and reads a verdict. No app, no login, no typing unless the code is damaged. On the premium label there are two codes: a shelf code anyone can check in the shop, and a hidden code under scratch foil that only the person who bought the pack can reach.
- credit per label
- 1
- per code, ~8 × 1014 combinations
- 10 chars
- camera to verdict
- < 2s
- apps to install
- 0
The life of one batch
Codes are born dead
A batch of codes moves through four states: generated, exported, activated, blocked. In the first two the codes verify nothing, so a stolen print file is worthless. Only activation, after printing quality control, makes them return a genuine verdict. Blocking a batch stops them again.
generated
Codes created
Made against credits. A stolen print file verifies nothing.
Verifies nothing
exported
Sent to the press
The file leaves the building. Still nothing verifies.
Verifies nothing
Printing QC activates
activated
Live on the shelf
Printing QC passes. Only now do the codes answer.
Genuine
blocked
Withdrawn
The brand blocks the batch, and every code in it stops.
Recalled
A leaked print file, an overrun or a reel that walks out of the factory is worthless here.
02 /How it works
Four steps, and the one that does the work.
- 1
Your printer generates a batch.
In the AVRA console, your print or packaging partner picks the brand, the product and the quantity, chooses what the batch is for, and generates it. One credit is deducted per label, atomically — two people generating at once cannot overspend the balance, and a browser retry cannot charge twice. A batch generated by mistake can be cancelled for a full refund while nothing has left the building. - 2
The print file goes to the press.
A background job builds three renderings of the same table: a CSV for variable-data printing, a ZIP of print-ready SVG codes, and an Excel bundle with the codes as images for handover. With them: a one-rowmanifest.csvnaming the batch, the label range, the scan limit and the dates, and aSHA256SUMS.txtso the printer can prove the file arrived intact. - 3
QC passes, and the batch is activated.
This is the step that matters. Until someone presses Activate, every code in the run answers exactly the same as a code that was never issued. Wastage, overruns, a roll that walks off the line and the print file itself are all worth nothing. After activation the print file stops being downloadable by the partner at all — it becomes platform-admin only, every look is audited, and the file is purged 30 days later. - 4
A consumer scans.
The camera opens a page. The page states a verdict, shows the brand's own logo, the product photo and up to five facts the brand chose — expiry, MRP, batch number, whatever the buyer can check against the pack in their hand — and offers one more action: report it, with a photo and a location.
One pack, two codes
A QR can be copied. The claim cannot.
One pack carries two codes. The visible shelf code, scanned before purchase, answers VALID and claims nothing. The hidden code is reachable only after purchase, answers GENUINE and claims the unit once. A photographed and reprinted shelf code answers SCANNED BEFORE.
- 1Valid
Shelf code, before purchase
Anyone can scan it. It claims nothing.
- 2Genuine
Hidden code, after opening
Scratch panel, cap seal, carton flap or pouch web. It claims the unit, once.
- ×Scanned before
A photographed, reprinted label
The copy carries only code 1, and that code has been seen already.
Three labels, and what each one actually protects.
Chosen per batch, because a ₹90 bottle and a ₹9,000 pump do not need the same thing.
| Mode | What is printed | What a scan claims | Choose it when |
|---|---|---|---|
| Dual | A shelf code and a hidden code under foil | The hidden code claims the unit once | You want the strongest answer available. This is the default for anything worth faking. |
| Single | One code, printed openly | The first N verifications read GENUINE; N defaults to 3 | The pack cannot carry foil, and you accept that a copied code gets N good answers before anyone is warned. |
| Information only | One code, printed openly | Nothing. Every scan shows the same page forever | You want a product page on the pack, not a verdict. This is not protection and we do not sell it as protection. |
N defaults to 1 on dual and 3 on single, is frozen at generation, and 0 means no limit.
No limit is how a certificate or a document meant to be shown to many people is configured.
03 /What your team sees
A batch page that can answer a dispute.
Every batch has a page, and the page carries its own history: who generated it, when, how many credits it cost, which product it belongs to, its scan limit, which second factor is printed on it, and how many of its codes have actually been verified. Not how many were scanned — how many were decisively verified, because a Dual Code's shelf scan answers “likely genuine” without claiming anything, and counting it would flatter the number.
04 /What the buyer sees
Two seconds, no app, your brand.
The verdict page is the brand's, not ours. Your logo, your product photo, your care number, your choice of up to five facts a buyer can check against the pack in their hand — and a line at the foot crediting the partner who printed the label. AVRA's own look is only the fallback when a brand has not set one.
It makes no third-party request of any kind. No font from Google, no analytics tag, no chat widget. A page that renders a security verdict should not be asking four other companies for permission to load.
Your brand
Sample
GENUINE
This code was issued by AVRA, its batch was activated after printing QC, and this scan is within the number of verifications its batch allows.
- Code
- 7XK2 M9PQ 4R
- Brand
- Your brand
- Product
- Your product
Powered by your print partner
Your brand
Sample
SCANNED BEFORE
This code has been claimed already. Do not assume it is fake and do not assume it is genuine — it can also be an opened pack or a resale. Report it and the brand will look.
- Code
- 7XK2 M9PQ 4R
- Brand
- Your brand
- Product
- Your product
Powered by your print partner
What GENUINE means, exactly.
GENUINE is not an opinion about the product in your hand. It is four facts about the code you scanned. This code was generated by AVRA, inside a named batch, for this brand and this product. That batch was activated by the printer after its print run passed QC. The code has not been verified more times than the batch allows. And this is one of those verifications.
That is what the platform can observe, and it is all it asserts. It does not mean the liquid in the bottle is the right liquid. It means the label on that bottle was issued once, released once, and has not been used up.
A counterfeiter who prints a perfect copy of your label gets one of two answers. We can't verify this code, because the code was never issued. Or SCANNED BEFORE, because the real buyer got there first. Neither is a GENUINE verdict, and both raise an alert — the second on the brand's dashboard, the first with us, because no brand owns a code that was never issued.
The full verdict vocabulary
| Verdict | Shown when | What it is evidence of | What the page tells the consumer |
|---|---|---|---|
| GENUINE | A hidden or single code verified within the batch's limit; or the same buyer re-scanning | The code was issued, released and claimed by you | Keep the pack. Product details below. |
| VALID | A shelf code on an unclaimed Dual Code pair | The code is real and nobody has claimed this unit | This code is real. Confirm after you buy, using the code under the foil. |
| SCANNED BEFORE | The claim limit is spent and this is a stranger's device | Someone already claimed this unit — a copy, or a pack opened before you | Do not assume it is fake, but do not assume it is genuine. Report it. |
| NO MATCH | A hidden code typed wrong | Either a typo, or a fake pack carrying a fake code | Check the code. Five wrong tries lock this label for a day. |
| We can't verify this code | The code was never issued, or its batch is not activated — the same answer for both | Nothing on the platform matches this code | Check it against the label. If it matches, tell us where you bought it, with a photo. |
| RECALLED | The batch was blocked after release | The brand withdrew this print run | Contact the brand's care number. |
Why an unknown code and an unactivated one read the same
A code nobody issued and a code from a batch nobody has activated get the same answer — “We can't verify this code” — and the same bytes from our server. That is deliberate. If the page told the two apart, anyone holding a stolen print file could scan it and learn which batches have not been activated yet, which is exactly what makes a stolen roll worth stealing.
Neither answer accuses the person holding the phone. The screen says we cannot verify the code, not that the product is fake, because a genuine pack from a batch whose activation was never recorded is sometimes our own error — and a second scan of a claimed code is amber, “scanned before”, never red, because it can also be an opened pack or a resale.
05 /Where it fails
What this does not do.
Every vendor in this category will tell you their code cannot be copied. A printed QR code is a picture, and a picture can be photographed. Here is what actually stops a counterfeiter, and where it stops working.
A copied code is still a code.
If a counterfeiter photographs your shelf label and prints it on ten thousand fakes, every one of those fakes carries a real code. What they cannot do is make it answer GENUINE — the hidden code is not on the photograph. What they get is VALID, which claims nothing, or SCANNED BEFORE once the real buyer has claimed the unit. Both are visible to you: repeated claims on one code from three or more distinct networks raise a clone-attack alert.
Genuine unused labels are genuine.
If labels are stolen from the print line before they are applied, and the batch is activated, those labels verify. This is a physical security problem at the printer, not a software problem, and it is why the physical feature and the platform are sold together: the label itself has to be hard to obtain. What the platform adds is that stolen unactivated labels are worthless, and ten of them being scanned in a week raises an alert.
A shopkeeper who opens cartons reaches both codes.
The hidden code is protected by the pack, not by cryptography. Someone with the carton open can scratch it. The consequence is visible — the buyer who gets that pack reads SCANNED BEFORE, and you see the alert — but the scan itself cannot be prevented.
Nothing works without a connection.
The code carries no verdict. It carries an opaque ten-character identifier, and the verdict is fetched. In a basement godown or a village with no signal, the scan page does not load. That is deliberate: a code that could answer offline would be a code that could be forged offline. The fallback is the typed-code form on /verify, which needs the same connection but not a working camera.
A scan limit is a warning threshold, not a guarantee.
N is how many copies of a code see GENUINE before anyone is warned. On a Dual Code label it is 1. On a single-code label the default is 3, because a real buyer scanning from two phones and a friend's phone should not be accused. Choose it deliberately.
We do not police the internet.
No marketplace takedowns, no listing monitoring, no test purchases. Four competitors sell that as a separate product; we do not have one.
06 /Integration
What your team has to do.
Nothing, in most cases. The work sits with the printer who already prints your label, and it is one extra column in a file they already produce.
Your brand is set up once.
Your printer gets a file, not an API.
The print spec is four lines.
You do not change your packaging.
A large order can be uploaded as a spreadsheet.
What is not built: no ERP or SAP connector, no GS1 Digital Link URL format, no aggregation to carton or pallet, no NFC or RFID, no vernacular scan pages yet.
07 /What it costs
One credit, one label.
A credit is a label. It is deducted when the code is generated and nothing else is metered — consumer scans are free, verdict pages are free, and there is no per-active-user charge. The price of a credit does not change with what the batch is for: an authenticity label costs the same credit as any other.
The rate for a credit depends on volume, and the finished label — the substrate, the print, any tamper-evident feature — is quoted by your printer or packaging partner. Ask for both together and you have the whole cost per unit.
08 /Questions
Questions.
Can a counterfeiter copy my QR code?
They can copy the picture. They cannot copy what it points at. A copied shelf code returns VALID — which explicitly claims nothing — and the moment the real buyer claims the unit with the code under the foil, every copy returns SCANNED BEFORE and you get an alert. What a copy can never return is GENUINE.
What if my printer prints extra labels?
They verify nothing. Codes are dead until the batch is activated after QC, and activation is a deliberate action by your print partner or by AVRA, not a side effect of printing. If those extra labels are scanned anyway, ten of them inside a week raises a print-file-leak alert on your dashboard.
Do consumers need to install an app?
No. The phone's own camera opens the page. If the code is damaged and will not scan, there is a page where it can be typed instead.
What happens when there is no mobile signal?
Nothing loads. The code is an identifier, not a certificate — the verdict lives on the server, because a verdict that could be produced offline could also be forged offline. We would rather say this than claim an offline mode we do not have.
Do I still need a hologram or another tamper-evident feature if the code is unique?
Yes, something has to do that job, and for a reason worth understanding. The code proves the label was issued by you and has not been claimed. Making the pack hard to obtain, hard to reproduce and visibly damaged when opened is a physical job — a hologram is the strongest common answer, but a destructible face stock, a VOID-release adhesive, a perforated tamper band or a seal that tears are all real ones, and a plain printed pack has none. Either half alone has a gap; that is why they are sold together. Which formats can carry which is in the substrate table on For printers and packaging companies.
How many times can one label be scanned?
As many times as anyone likes. What is limited is how many times it is claimed. On a Dual Code label that is once; on a single-code label the default is three. Your own re-scans of a label you already claimed never count against it.
What happens to my printed labels if we stop using AVRA?
A label you have paid for keeps answering. Stop buying credits and you stop making new labels — the ones already on shelves go on verifying, because the credit was spent when the code was made.
What lapses, fifteen days after a subscription ends, is platform access: the dashboard, exports, new batches, message sending and reward payouts. The whole answer is on If you stop paying.
Can I put a code on something that is not a product?
Yes. A certificate, a calibration report, a training record — a run of codes for documents works the same way, with the issuer's own fields and a public page at /c/<code>. See Certificates and documents below.
Certificates and documents
The same code engine issues runs of codes for documents rather than products: a degree, a calibration report, a training certificate. The page at /c/<code> is tamper-evident for one reason — the QR carries nothing but an opaque code, so every field a verifier reads comes from the issuer's record at scan time and a forged QR cannot carry forged data. It shows the certificate and nothing else: no scan count, no location, no “verified 14 times”.
Next
- AVRA SignalEvery verdict here becomes a row on your dashboard.
- AVRA RewardsThe same hidden code can carry a cashback for the trade.
- PricingThe credit tiers, and what a label costs end to end.
- GlossaryBatch activation, single-use code, tamper-evident.
- For partnersHow a printer, converter or packaging company sells this under its own name.
Print one batch and scan it yourself.
The fastest way to judge this is a sheet of real labels and a phone.
Trust, made visible.
connect@avrascan.com · +91 91737 47583 · Navacara Infotech, Ahmedabad, Gujarat, India