Get started
All posts

qr code ticketing

QR Code Ticketing: What the Scan Must Prove

October 2, 2026 · 4 min read · 986 words

A QR code ticket is a single-use claim encoded in an image. Everything that matters about it happens at the door: whether the scan can be trusted, whether it still works when the venue wifi does not, and whether one ticket can be admitted twice.

What is QR code ticketing?

QR code ticketing is the practice of issuing each ticket as a unique code that a scanner reads at entry to validate it. The code is not the ticket; the record behind it is. The scanner looks up the code, checks the record, and marks the ticket used - which is why the same image stops working once it has been admitted.

That distinction separates a QR code that merely identifies an order from one that enforces admission. The first can be screenshotted, forwarded and shared. The second is invalidated the moment it is scanned, so sharing it just means one of the two people is turned away.

What a QR ticket has to contain

A trustworthy QR ticket encodes a value that cannot be guessed and cannot be reused. At minimum it should carry:

  • A unique token per ticket rather than per order - an order for four seats is four separate codes.
  • The event and the ticket tier the code admits to, so a general-admission code cannot pass the VIP door.
  • A validity window, so a code issued for tonight is not honoured on a different date.
  • A signature or nonce proving the platform issued the code, which is what stops anyone generating a valid-looking one.
  • Optionally, a holder reference, so a lost ticket can be reissued without a second valid code existing at the same time.

How the scan should validate a ticket

Validation is a state change, not a lookup. The scan should move the ticket from valid to used atomically, so two doors reading the same code in the same second cannot both admit it. If the check and the write are separate steps, the gap between them is exactly where duplicate admissions get through.

A workable scanner resolves the code into one of a small set of outcomes, and each outcome is visible to staff on the screen:

  • Accepted - the token is valid, unused, in window and matches the tier for this door.
  • Already used - the token exists but has been consumed, with the time and gate it was first scanned.
  • Wrong tier - a real ticket presented at a door it does not admit to.
  • Cancelled or refunded - the token was voided after issue and must never admit.
  • Not found - the code is not in the issued set, which usually means a forged or foreign ticket.

How the ticket reaches the door

Delivery is part of the design, not an afterthought: a code that exists only inside a web page fails the moment a guest cannot load the page. Real programmes plan for more than one route.

  • Email, with the code as an image and as a link, so it renders even when images are blocked.
  • A wallet pass, which keeps the code available with no network connection.
  • A will-call list for guests whose message never arrived, looked up by name at the desk.
  • A staff-issued reprint for a phone that died - which is why the reissue path has to invalidate the original code.

Can scanning work without internet?

Yes, if the scanning device holds a signed list of valid codes locally and reconciles with the server later. The design has to accept what that costs: while offline, the device can only refuse a second scan of a code it has already seen, so the rule must be that an offline scan consumes the token on that device rather than merely reading it.

The reconciliation is where duplicates surface, and it should produce a report rather than a silent fix, so a promoter can see whether two gates admitted the same ticket and act on it before the next event.

What to test before the doors open

The failures that ruin an entry queue are all reproducible in an afternoon, which is when they should be found:

  • Scan the same code twice on two different devices and confirm the second is refused.
  • Scan with the venue wifi off, then reconnect and confirm the offline scans sync without double-admitting anyone.
  • Present a general-admission code at a tiered door and confirm the rejection names the tier rather than failing silently.
  • Present a refunded ticket and confirm it is rejected with a reason staff can read aloud.
  • Reissue a ticket and confirm the original stops working immediately.

Frequently asked questions

Is a QR code ticket secure?

Only if the code is a signed, single-use token and the scan actually enforces that single use. An unsigned code that just displays an order number can be copied and shared. The security lives in the validation step at the door, not in the image the customer holds.

Can two people use the same QR code?

Not if the platform marks the ticket used on the first successful scan. Where duplicates get in, it is usually because the validity check and the state change were separated, so two gates both read the ticket as valid before either wrote it back.

Can QR tickets work without internet at the venue?

Yes, if the scanning app holds a signed list of valid codes locally and reconciles afterwards. The offline rule has to consume the token on the device at the moment of scanning, otherwise a reconnection can admit the same code twice.

What is the difference between a QR code ticket and a barcode ticket?

Both encode an identifier a scanner reads, but a QR code holds far more data and tolerates partial damage better. That capacity is what lets it carry a signed token directly instead of pointing at a lookup key the scanner has to fetch.

Related on ShopDango

Run your next sale on your own domain

ShopDango gives each client a branded storefront and gives the operator one console for every store - auctions, events, rentals, subscriptions, and retail together.