A candidate sent you a Profile share. Before you trust it as evidence, you want to verify it's genuine — that QLM actually issued it, that the candidate didn't forge or alter it, that it's still active. The verification infrastructure is public, free, and works without QLM account creation. Cryptographic verification of every share, with five distinct checks plus methodology version alignment.
Paste the share token or follow the share link. The verification page returns five checks plus the Profile content the share is authorized to display. If any check fails, the page returns "verification failed" with a specific reason — the recipient sees clearly that the share is invalid, expired, revoked, or otherwise not trustworthy.
Recipients verify shares in different ways depending on their workflow. Three integration paths: web verification page for ad-hoc verification, REST API for systems integration, and ATS/HRIS partner integrations for inline verification.
Recipient pastes the share token or follows the share link. Five checks complete in <5 seconds. No account required.
REST endpoint at /v1/verify. Standard JWT verification tooling supported. 10K queries / hour rate limit free; higher tiers paid.
ATS / HRIS partners surface verification inline in the candidate record. Recipient sees verification status without leaving their workflow.
QLM's commitment is that verification works without QLM account creation, without payment, without rate-limiting that excludes legitimate small-volume recipients. The verification infrastructure exists primarily to support the brand's portability commitment — Profile share without verification is not really portable. Standard public-key cryptography, well-understood signature algorithm, no proprietary protocols.
ed25519 signing for every Profile artifact. Standard JWT tooling supported across languages. Public key published at well-known URL; key history available for historical share verification.
Generous free tier supports legitimate small-volume recipient use cases. Higher tiers available for high-volume integrations (e.g., ATS surfacing verification on every candidate record).
Verification API SLA. If verification is offline, share recipients can't establish trust — uptime is foundational to the brand commitment, not a luxury feature.
Verification establishes that the Profile is genuine and authorized for display. It does not interpret the Profile, recommend hiring decisions, or replace the recipient's judgment. Five things verification does not do.
Verification is free for recipients. The portability commitment requires it. Higher-volume integrations (ATS partners, large-scale verification deployments) tier into paid plans for SLA and rate-limit upgrades; small-volume legitimate recipient use is free.
Web page + REST API verification, 10K queries/hour, no account required. Covers the vast majority of legitimate recipient use cases. Foundational to the brand commitment; not pricing-experiment territory.
For very high-volume integrations beyond 10K/hour. Includes 99.99% SLA, dedicated rate-limit pool, support for cached verification. Useful only for ATS partners, recruiting platforms with massive verification load.
ATS / HRIS partners that surface verification inline in their candidate workflow. Negotiated case-by-case with OEM partnership tier.
Five checks complete in under five seconds. Free, no account required.