A Shopify app by Monochrome

Every item gets a number.
The number gets a record.

Provenance mints a unique identifier for each physical item you make, prints it on a card as a QR code, and answers when somebody scans it. What comes back is the item itself: model, colourway, photograph, the date it was made, which of the edition it is. Held in a register inside your own Shopify admin, which stays yours.

Does it prove an item is genuine? No. Here is why not.

In development · Not yet on the Shopify App Store

Identity, not a verdictNo green tick anywhere in it
The register is yoursIt survives uninstalling us
No customer dataNo names, no emails, no prices
Data in the EUFrankfurt, encrypted at rest

How it works

Mint, print, scan

Three steps, and the middle one is the one most systems leave you to solve on your own.

01

Mint

Pick a product and a quantity. Provenance generates that many identifiers, writes them into your register, and refuses to issue the same one twice. A run can cover several products at once.

  • Identifiers carry no structure, so they leak no production volume
  • Uniqueness is a database constraint, not a hopeful code path
  • Limited editions are numbered as they are minted
02

Print

Download a print sheet, one card per identifier, with the code as text underneath it. Or take the vector QR files and the merge-ready CSV into InDesign and use your own card design.

  • Grouped by product, so a mixed run cannot be shuffled
  • Marking a run printed freezes it, on purpose
  • Cards point at your address, not ours
03

Scan

The card resolves on a page inside your own theme. Whoever is holding the item sees what it is. A code that was never issued says so plainly, in the same shape and at the same speed as one that was.

  • Nothing to set up: the page exists from install
  • The identifier travels in the URL fragment, so no server sees it
  • Status shows, including the bad kind

The whole path, step by step

The idea

Why there is no "Authentic" headline

Every competing product answers yes or no. This one refuses to, and the refusal is the whole design.

  • A verdict is copied along with the code. Buy one genuine piece, photograph its card, and stamp that code onto five hundred fakes. Every one of them now verifies. The system says yes five hundred times and is right once.
  • An identity gives itself away. Return the item instead of a judgement and the person holding a brown bag whose code resolves to a black one has their answer immediately. The forger would have to copy a different code onto every fake, and match each one to the right object.
  • A printed word is reproduced perfectly by a photocopier. A live lookup is not. That is the only meaningful difference between a certificate and a register.

The certificate follows the same rule. It is headed "Certificate of registration", never "of authenticity", and it renders bad news: an item reported lost or stolen says so, prominently. A document that can only ever flatter its holder is worth nothing.

Beyond the lookup

A record is the start of it, not the whole product

Generating a code is the easy part. The work is everything around it: getting the codes onto physical cards, keeping the record true after the item has left, and holding all of it somewhere that outlives us.

The register, in your admin

A metaobject definition created in your own Shopify store on install. Your data, in your account, exportable, and still there if this app disappears. Our database is the system of record; that is the mirror you keep.

The print package

Vector QR codes and a merge-ready CSV, zipped, for an InDesign data merge. Or a standalone print sheet if you want cards today without a designer.

Certificates

An A4 document per item, rendered on demand from the register rather than stored, so it cannot go stale. Your design, our rules about what it may claim.

Editions, numbered at mint

Number 7 of 10 is assigned when the identifier is created and continues from what that variant has already been minted, so a second run does not restart at one. A run that would exceed the edition size is refused.

Status, including the bad kind

In stock, sold, lost or stolen. A report shows on the lookup and on the certificate. Clearing one requires a reason, and every transition is recorded with who made it.

The event history

Every item has its own page and its own log: minted, mirrored, printed, sold, reported, cleared. Which is what makes it a register rather than a list.

Every feature, in full

Being straight with you

What Provenance is not

It publishes what you record. That is a genuinely useful thing and it is also the ceiling, so it is worth saying here rather than burying it in the terms.

  • It does not verify anything. If you record that a bag was made in March from Adria leather, the register says so because you said so. We do not check it, audit it or certify it, and a claim you cannot back up is your liability rather than ours.
  • It is not an anti-counterfeiting system. It makes a particular kind of fake easy to spot: the one carrying a copied code that resolves to a different object. It does nothing about a fake with no card at all, and nothing about a forged card whose code was never issued beyond saying that code is not in the register.
  • It is not a chain of custody. The register records what you write to it, not where the object has physically been. Nobody scans it into a warehouse and nobody signs for it. Status changes are typed by a person or driven by a Shopify event.
  • A lookup needs us to be up. Unlike a merchandising app that can fail open, a scan is a live request. During an outage a card does not resolve. Your store keeps working, because none of this sits in the buying path.

The full version is in the Terms of Service, and the FAQ answers the same questions one at a time.

Want a register for what you make?

Tell us what you make and how many of it. We will tell you honestly whether this helps, including if the answer is that a spreadsheet and a good photograph would do.