CertLister Help
Go to app
On this page

Advanced Features

Add a Recipient Photo to a Certificate

Put each person's photo on the certificates you issue: place the photo frame once in Design Studio, then add the photo when you issue the credential.

Add a Recipient Photo to a Certificate

Time to read: 5 minutes


Overview

A credential can carry one photo of the person it was issued to. That is what turns a printed credential into something a person can be recognised by — a site pass, a licence card, an ID card worn on a lanyard.

It takes two steps, and only the first is a design job:

  1. Place the photo frame once, in the design the credential uses.
  2. Add each person's photo when you issue them, in the Issue Credential drawer.

The photo is then drawn inside the frame every time that credential's PDF or wallet card is generated. Photos sit alongside the rest of the certification tracking and verification software.

PlanBasic and Pro
File typesJPEG or PNG, up to 5 MB
Photos per credentialOne
Appears onThe credential PDF and the wallet card
Public verify pageStill confirms the credential. By default it offers no PDF or wallet card download; an issuer can turn that on per category
RoleAdmin or Manager

Recipient photos are part of the Basic and Pro plans. Designing with the frame is not restricted — you can place it and save the design on a free account, and you are only asked to upgrade at the point you try to add a real photo.


Step 1: Place the Photo Frame in Your Design

  1. Click Design Studio in the left navigation, or open a saved design
  2. Pick the canvas you are designing: Credential or Wallet card
  3. Open the Attributes panel in the tool strip on the left
  4. Under Recipient photo, click the tile or drag it onto the canvas
  5. Move and resize the frame where you want it, then Save the design

A few things to know:

  • The frame starts as a portrait rectangle, three units wide by four tall, and it cannot be rotated. Resize it to whatever shape you need; each photo is scaled and cropped to fill it, so nothing is stretched out of proportion.
  • One frame is enough. The frame is a slot, not an image — it holds whichever photo belongs to the credential being generated.
  • There is no photo frame on the badge canvas. Badges are square and generated at a small size; the frame is offered on the credential and wallet card canvases only.
  • A credential with no photo prints nothing there. The frame is a guide in the studio, not something drawn on the file, so a design with a frame still produces a clean credential for people who have no photo.

Step 2: Add the Photo When You Issue

  1. Click Credentials in the left navigation, then New credential
  2. Fill in the recipient's details as usual
  3. Under the recipient's fields, click Add photo and pick a file
  4. The photo uploads straight away and a thumbnail appears in its place
  5. Issue the credential

Each recipient row in the drawer has its own photo slot, so a batch of ten people can be given ten different photos in one pass.

A few things to know:

  • JPEG or PNG, up to 5 MB. Anything larger, or any other file type, is refused with a message saying so. We re-encode every photo we accept and remove its metadata, including any GPS location the camera recorded.
  • Wait for the upload to finish. Issuing is held until every photo on the form has uploaded — a second or two on a normal connection.
  • A draft does not keep the photo. Save a recipient as a draft and their details are kept, but the photo is not. Add it again at the moment you issue.
  • On a free account the button is locked, and clicking it offers the upgrade instead.

Replace or Remove a Photo

Open the credential's row actions and choose Edit. The photo appears under the recipient's fields with two controls:

  • Replace photo — pick a new file. The old one is deleted. Save the edit, and the credential's PDF and wallet card are marked Details changed in the table: that chip means the file on record was made before this edit, so it still shows the old photo. Regenerate the PDF and the wallet card to bring them up to date.
  • Remove photo — the credential keeps everything else and goes back to having no photo.

Removing the photo also removes the credential PDF and the wallet card that CertLister generated from your design. The face is drawn into those files, so they go with it when you save. Generate them again and you get new ones, with no photo on them. A PDF you uploaded yourself is kept — it is your own file, so if it shows the person's photo, replace or delete it yourself.

Removing a photo is never blocked by your plan. If an organization moves to a plan without photos, existing photos stay on the credentials that have them and the Remove photo button keeps working — the one control that takes a person's face back off a file should never be behind a paywall.


Why the Verify Page Stops Offering the File — Unless You Turn Publishing On

A photo is drawn into the PDF and the wallet card. Publishing those files would publish the face, so by default a credential that carries a photo does not hand its files to the public verification page. An Admin or Manager can lift that restriction for a whole category: see Publish Photos for a Category below.

By default, the page still does its job without handing out the file. Someone who looks the credential up sees the credential record and can confirm it is real. What they do not get is a Download Credential or Download Card button, or a preview image of either. A credential with no photo is unaffected and behaves exactly as before.

Who can open the file while a category keeps publishing off:

  • Your team. Signed-in members of your organization open the PDF and the wallet card in the app as usual, from the Credentials table or the credential's drawer.
  • The recipient. They get the PDF where you attach it to the issuance email, or where they sign in to your recipient portal, if you have turned it on. Both are settings you control, so decide which route you want before you issue.

Publish Photos for a Category

An Admin or Manager can turn on Show recipient photos on the verification page for a category, in that category's settings. Turning it on changes what the public page offers for every credential in that category — past and future, not only new ones:

  • The photo appears on the page beside the recipient's name.
  • The Download Credential and Download Card buttons appear, so anyone who finds the credential on your verification page can get both files.
  • The page finds a credential by its number or by a name search: anyone who types three or more letters of a name sees up to 25 matching credentials, with the photo of each one in a published category. No credential number is needed.

What does not change. The preview panel never shows a photo, on any plan, whether or not a category publishes them — see Where the Photo Goes, and Where It Does Not below. The photo itself is still served as a short-lived signed link behind the scenes, not as a permanently public file; the switch decides who that link is handed to, not whether the storage bucket becomes public.

Before you turn this on: make sure the people in that category have agreed to their photo being public, and see Two Things to Do Before You Publish below for what the name search shows and the renewal practice that goes with it. You can turn the switch off again at any time — the public page reverts to the default for that category's credentials immediately, though anyone who already downloaded a file keeps their copy.


Where the Photo Goes, and Where It Does Not

The photo is stored privately. It is always handed out as a short-lived link, never as a permanently public file — by default only to signed-in members of your organization, and also to the public verification page once you publish photos for that category.

It goes when the credential goes. Deleting a credential, or returning it to draft, deletes its photo along with the PDF, the wallet card and the badge. Deleting your organization deletes all of them.

We treat a recipient photo as an ordinary image. We do not run face recognition on it and we do not derive any biometric data from it. Our Privacy Policy and Data Processing Addendum say the same thing in the language a customer's legal team will ask for.


Two Things to Do Before You Publish

If you turn photo publishing on for a category, two habits keep it from turning into a bigger exposure than you meant:

  • Treat the whole category as findable by name. Your verification page's search matches any three or more letters of a recipient's name, so someone who types a common fragment such as "son" sees the photos of up to 25 people at a time. Random credential numbers do not change this. Publish only a category whose people have all agreed to their photo being public.
  • Replace the photo at renewal, don't carry it forward. Renewing a credential copies the predecessor's photo file onto the new one, so the new credential's issue date is not a guide to how old that photo actually is. If the person's appearance has changed, or the original photo is no longer the one you want public, replace it when you renew.

FAQ

Q: Can one credential hold more than one photo?

A: No — one photo per credential, and it belongs to the recipient. If your design has two frames on it, both show the same photo.

Q: I placed the frame but the photo is not on the PDF. Why?

A: Two likely reasons. Either the credential has no photo — check its row in the Credentials table — or the PDF was generated before the photo was added, in which case the row shows a Details changed chip and regenerating fixes it.

Q: Does the photo appear on the wallet card as well?

A: Yes, if you place a frame on the wallet card canvas. The two canvases have separate designs, so a frame on the credential does not put one on the card.

Q: Why does the verification page offer no PDF download for some credentials?

A: Because those credentials carry a recipient photo, and the photo is drawn into the PDF and the wallet card. By default both files are kept off the public page for that reason, unless an Admin or Manager has turned on photo publishing for that credential's category. See Why the Verify Page Stops Offering the File — Unless You Turn Publishing On above for where your team and the recipient can open the files either way.

Q: Can recipients see or change their own photo?

A: They cannot upload or change one — adding, replacing and removing photos is an Admin or Manager job inside your organization. They see their photo where it is drawn: on the credential PDF wherever you have given them that file (attached to the issuance email, or in your recipient portal if you have turned it on), and on the public verification page too if your organization has turned on photo publishing for that category.

Q: I am on a free account. Can I still build a design with a photo frame?

A: Yes. Place the frame, position it and save the design as usual. The upgrade prompt appears only when you try to attach a real photo to a credential.

Q: What happens to the photo when I renew a credential?

A: The replacement credential gets its own copy of the photo, so deleting either one leaves the other untouched.

Q: Which file formats work?

A: JPEG and PNG, up to 5 MB each. We convert what you send to a single consistent format and strip its metadata, so a photo taken on a phone does not carry its location onto your credential.

Still stuck? We respond within 24 hours on business days. Contact support →