Scan app and scanning staff
Pairing a device, scanning without a network, and what you do with a device that goes missing.

At the door you scan tickets with a phone. This article explains what the scan app does, how you get it onto an Android device or an iPhone, how you give somebody scanning rights, and what you say to the visitor whose ticket shows as "invalid". After this article there will be a working device at your entrance and you will know who may operate it.
What does the scan app actually do?
On every ticket there is a QR code: that pattern of little blocks you also see on a train ticket or on a packet of coffee. Hidden in those blocks is a long, unique code — a kind of serial number that exists only once.
The scan app does exactly one thing with it. You hold the phone's camera in front of that QR code, the app reads the code, and in less than a second it tells you whether that person may come in. Nothing more. There are no prices in it, no turnover, no sales figures — the people at the door do not need to see that and so are not given it.
After a valid scan that ticket is used. Anyone offering the same ticket a second time — because they forwarded it to a friend, for instance — gets a message that it is already in.
The technical words from this article are also in the glossary.
What you need beforehand
- A phone or tablet with a camera, Android or iPhone, one per entrance.
- The owner role in the back office, to invite somebody as a scanner. Only an owner can invite staff.
- Your organisation's organisation code: a short identifier without spaces,
such as
demo-bezoekerscentrum. You find it in three places: in the address bar of your back office, right after/app/; under Settings → Organisation, in the field Organisation code; and at the top of the Staff page. It is also in every invitation e-mail. - The email address of every person who is going to scan.
- Half an hour, the first time. After that, getting a device ready is two minutes' work.
Step 1 — inviting somebody as a scanner
A scanner is a staff member with exactly one right: scanning tickets. They cannot change products, cannot see orders and cannot refund money. That is deliberately so narrow: at an entrance there is often a volunteer helping you for one evening.
- In the back office, go to Settings → Staff.
- Click Invite a staff member and fill in the email address and the name.
- Under Role, choose the Scanner role.
- The person gets an email with a link to choose a password. That link stays valid for 60 minutes. As soon as they choose their password with it, they are active and their email address is confirmed straight away. If they already had an account, they become active at their first sign-in.
The full explanation about roles is in Staff and roles.
Note: invite every scanner separately. One shared account with a password that goes round on a slip of paper seems handy, but then you can no longer see afterwards who scanned what — and you cannot take access away from one person without shutting all the others out.
Step 2 — putting the app on the phone
Installing an app means: fetching the programme onto your phone from a store. Which store that is depends on your device.
An iPhone or iPad
The app is in the App Store, the blue icon with a white "A" made of brush strokes. On the device itself, open Passavo in the App Store, tap Download and confirm with your device code, Face ID or Touch ID. You can also simply search the App Store for Passavo.
After half a minute the icon is on your home screen. You get updates automatically after that, just like your other apps.
An Android device (Samsung, Google Pixel, Xiaomi, …)
Android devices fetch apps from the Play Store, the coloured triangle that is on the device by default. For Android we send you the link: tap it, the Play Store opens on the right page, and you tap Install. Feel free to ask for it at support@passavo.eu — you get it the same working day.
Through TestFlight, if you are given a test version
TestFlight is Apple's testing service. We use it to give a new version to a small group first, before it reaches the App Store. So it is not a different app and not a lesser app — it is the same app, through a different door. If you have not had an invitation, you can ignore this: the ordinary App Store is enough.
This is how that goes:
- You get an invitation by email from us at the address you gave.
- You first install TestFlight itself from the App Store. That is a free app from Apple, an orange icon with a little white aeroplane.
- You open the invitation email on the phone and tap the button in it.
- TestFlight opens and shows the app. You tap Install.
Note: a TestFlight invitation is personal and belongs to one email address. Do not forward the email to a colleague — they cannot do anything with it. Do feel free to ask us for a second invitation; it costs nothing.
Step 3 — signing in
Open the app. You see three fields.
| Field | What you fill in |
|---|---|
| Organisation code | Your organisation's short identifier. Capitals make no difference |
| Email address | The address the scanner was invited with |
| Password | The password they chose themselves |
The organisation code makes sure the app knows which organisation to knock on. There are hundreds of associations on the same platform; without that code an email address would not be enough.
If signing in works, the device appears in the back office under Point of sale → Devices, with the make and model of the phone as its name. Give it a name there that matches reality ("Gate 2", "Side entrance"): click Edit next to the device and change the Name. When there is a problem, that name is the only thing that still helps you.

Note: if signing in does not work, you see two different messages, and the difference matters. "Incorrect sign-in details" means that the code, the address or the password is wrong. A message about a missing scanning right means that the account does exist but lacks the scanner role — then you have to go back to step 1.
After five failed attempts within a minute the app waits a moment. That is not a fault; it stops somebody sitting there guessing passwords.
Step 4 — fetching the manifest
When signing in, every time you open the app while there is a network, and whenever you ask for it yourself, the app fetches a manifest: the list of tickets for today. Think of the guest list a doorman holds in his hand. You refresh it yourself in the app under Settings → Refresh manifest.
With it, the app can carry on scanning when the network drops out, and it does drop out. In a cellar, in a marquee, in a field with three hundred people all glued to their phones.
The app decides every scan itself, against that manifest, and shows the answer straight away. As soon as there is a connection, it sends its scans on. You notice nothing of that at the door.
The manifest contains no ticket codes but only their fingerprint — an irreversible calculation on the code. So a stolen device with a downloaded manifest produces not a single usable QR code.
Refresh the manifest shortly before the doors open. A ticket sold after the last refresh is not on the device. How the app deals with that is explained below.
Tickets sold after refreshing
A ticket sold after the manifest was fetched is not on the device. From version 1.2 of the app, this is what happens:
- with a network connection the app checks such a code online straight away and shows the answer: valid, with the product and the name, or invalid. That takes a few seconds at most. A second scan of the same ticket is then recognised by the device, even without a network;
- without a network that is not possible: the app then says invalid and puts the scan in the queue. If you sell at the door while scanning, make sure the devices are online.
Test tickets. A ticket from a test order (paid in your payment provider's test mode) never grants entry. The app then shows Test ticket — no entry. Whoever shows such a ticket has not really paid: send them to the desk.
What you see on the screen
| Result | Meaning |
|---|---|
| VALID | Let them in. The ticket is now used. |
| CHECK | This ticket has already been scanned; the screen shows at what time. With a season pass: it has already been in today. |
| INVALID | Do not let them in without checking. The code is not on the manifest (unknown, forged, or sold after the last refresh), the ticket has been cancelled or refunded, or a season pass is blocked or not valid on this day. |
As well as a colour, every result also has an icon and a word. That is not excessive: at an entrance people stand in bright sunlight or with a colour blindness, and colour alone is then not a signal.
With a valid scan you also see the product and, if there are any, the time slot and the visitor's name. If the ticket was sold through a reseller, that name is alongside. That looks like a detail until somebody stands in front of you with a voucher from a booking site: you then know straight away who to refer them to.
What do you say with "check" or "invalid"?
This is the hardest part of the job, and it has nothing to do with technology. A few sentences that work:
- "This ticket shows as used. Have you perhaps already been in, or has somebody else been given the same code?"
- "I am not getting a green screen here. May I ask you to step aside a moment, then we can work it out together and I can keep the queue moving?"
- "I cannot let you in here with this code, but my colleague at the desk can look up your order."
Three things you do not do: argue in the queue, call somebody a forger, or let them in anyway because it is busy. Move the person aside, let the queue carry on and have somebody with access to the back office look up the order. See Following up orders.
How to keep a queue moving
The app scans quickly. The queue comes to a standstill for entirely different reasons.
- Turn the brightness of the visitor's phone up. The camera does not read a dark screen. Simply ask: "Could your screen be a bit brighter?"
- Case off. A tinted protective film or a flip case over the screen is the most common cause of a scan that fails.
- Let the visitor offer their screen, do not take their phone from them. It is quicker, and you are not responsible if something is dropped.
- Say beforehand where they should stand. A sign ten metres before the door saying "Have your ticket ready" wins more time than a faster app.
- Paper scans too. A printed ticket on white paper, held flat, is often the quickest scan of the evening.
- In bright sunlight: stand with your back to the sun, or hold your own body as shade above the visitor's screen.
Several entrances
Every device scans independently. Do feel free to use four at one door. Scans are kept as separate observations: who scanned what and when stays visible, even when two devices see the same ticket shortly after one another.
Note: a device does not know straight away what another device has scanned. It only learns that when it refreshes its manifest. If somebody offers the same code at two entrances shortly after one another, the second device may therefore still show VALID. Afterwards that second scan does show as Already scanned in the back office: under Settings → Staff, at the staff member under Details, in the Scans list.
A device lost
A phone that goes round at the entrance goes missing one day. Then do this, in this order:
- Take the scanning right away from the user who was signed in on that device. Go to Settings → Staff and click Delete next to that person; their access to your organisation then disappears. The scanning right is checked again on every request, so the device drops out at the next synchronisation.
- Have that person change their password, so that it is not possible to sign in again either. If they need to scan again later, invite them again.
- Set the device to inactive under Point of sale → Devices (open it with Edit and switch Active off), so that it is no longer in your list as usable.
- Then simply sign in to the app on the replacement device. It appears in your list as a new device by itself.
The device identification is stored hashed with us, so even a copy of the database produces no working device. And as it says above: the manifest on the lost device contains no usable codes.
Checklist: an hour before the doors open
- Every scanning device is charged or is on a power bank.
- Every device is signed in and shows the right organisation name.
- The manifest has been refreshed on every device.
- The screen brightness is turned up and the automatic lock is set to at least two minutes.
- You know who is at which entrance and who can open the back office when a ticket has to be looked up.
- There is a spare device ready, or at least a second phone with the app on it.
- Your scanners know what to say with "invalid".
- Are you also selling at the door? Then every scanning device has a network, so that you can refresh the manifest again after a sale.
The same app does more than scan
The app is not only a scanner. Anyone who signs in with the desk, administrator or owner role gets a home screen with two tiles after signing in: Scan and Till. The second opens the full counter till inside the app itself, on an iPad or an Android tablet — handy at a table where you sell as well as scan. At the top there is a button to switch quickly.
Nothing changes for your scanning staff. Anyone with only the scanner role does not see that home screen: after signing in the app goes straight to the scanning screen, as always. No prices, no amounts and no sales figures are added.
How to set the till up on a tablet is in The counter till.
Common mistakes
- One account for all the scanners. You then cannot see who scanned what and cannot shut one person out. Invite everybody separately.
- Not refreshing the manifest. Tickets sold this morning are then not on the device and get INVALID. Refresh just before the doors open.
- Signing out with scans still waiting. Scans that have not been sent yet are lost when you sign out. Look under Settings first: does it say "Everything sent"? If not, tap Send now.
- The phone on automatic lock after thirty seconds. Your scanner spends the whole evening unlocking their device. Set that longer.
- Forwarding a TestFlight invitation. It belongs to one email address. Ask for a second invitation.
- Arguing in the queue about an invalid ticket. Move the person aside and let the queue carry on.
What if …
What if the camera reads nothing?
Check three things, in this order: is the brightness of the visitor's screen turned up, is there a case or film over it, and is the camera lens of your own device dirty. A lens that has spent an evening in a trouser pocket is cloudy. A wipe with your sleeve solves more than you would think.
What if there is no network at all?
Then the app carries on scanning against the manifest it already has. You notice nothing of it. The scans go into a queue on the device and are sent on as soon as there is a connection again — that may be hours later.
What is not possible then: recognising a ticket that was sold after the manifest was fetched — the app shows that as INVALID. If you are selling at the door while scanning is going on, make sure there is a network at the entrance and refresh the manifest after such a sale.
What if the same ticket is scanned twice?
On the same device the second scan reports CHECK, with the time of the first scan. On a different device that only works after that device has refreshed its manifest; see "Several entrances" above. The first scan remains the valid one. If an older scan only comes in later because a device was offline, the time of entry shifts to that earliest moment: the order in which people really came in weighs more heavily than the order in which the network passed it on.
What if a visitor cannot find their ticket?
Look the order up in the back office and resend the confirmation email. You can also tick the visitor off in the app itself: look them up by name on the Today tab and tap Check in. That counts as an ordinary scan.
What if the scanner's phone is flat?
Hence the spare device in the checklist. A second device signs in, fetches the manifest and works straight away. The scans from the flat device still come in as soon as it goes on again and has a network — that may be the next day, as long as nobody signs out on that device in the meantime.
Frequently asked questions
Does the app cost money? No. The app is part of your subscription. What you do need is a device that can run it.
How many devices may I use? As many as you have entrances. Every device scans independently and keeps its own queue.
Do my scanners see how much turnover we have done? No. There are no prices, no amounts and no sales figures in the scan app. They only see what is needed to let somebody in.
Do season passes work in the scan app too? Yes. A season pass carries the same kind of QR code and is in the same manifest, with the number of visits it may produce per day. See Season passes.
Does every scanner have to have their own device? No, the device belongs to the entrance and not to the person. If somebody changes shift, they can carry on on the same device — but the scans are then in the name of whoever is signed in. If you want to keep track of that precisely, have the new team sign in again. Before signing out, tap Settings → Send now, or the scans still waiting will be lost.
Updated on 2026-09-24
Read next
-
At the door
Wallet passes
The ticket in Apple Wallet or Google Wallet, and what has to be set up for it.
-
At the door
The counter till
Selling at the door, with a till journal that cannot be changed afterwards.
-
At the door
Reviewing till sessions and Z reports
Every shift at the till in one list — with the cash difference, the Z report and the expor...
Still stuck? Write to us at support@passavo.eu