Every record with a credential has a public page at https://3dwarden.com/verify/<public_id>.
Anybody holding the address can read it. Nobody can list them, and a guessed id reads as nothing.
What it says
The page carries your organization's name, and its logo where one is set in Organization. Then two separate lines: whether the certificate is genuine, and whether the membership is currently active.
| You sent | The page says |
|---|---|
normalized_state: active | A genuine certificate, active, and what it authorizes. |
normalized_state: inactive | A genuine certificate that is not active. What it authorized is not shown. |
normalized_state: unknown, or no sync for 72 hours | The current status is not verified. |
credential.retired: true | The credential was withdrawn. The page keeps resolving. |
| The record was erased | No longer published. The page names the issuer, with its logo where it has one, and nothing about the holder: no name, license id, date or links. |
It lists public storefronts as registered by the holder or hosted by the issuer, and only while the membership reads active. A lapsed, withdrawn or unconfirmed record shows no shop links. They come back when a sync says active again. It never calls a storefront verified, because Warden does not check who controls an account.
It does not print the creator's own rules. publish_terms is still accepted on a credential and
the page draws nothing from it: a rule shown beside a holder's name reads as a judgment about that
holder, which is exactly what this page refuses to make.
What it does not say
The page does not say the seller follows the creator's terms, and Warden does not treat membership
as clearance. It carries none of your private fields: not your external_id, not your provider
name, not status or tier.
The page asks search engines not to index it.
Point your certificates at Warden
New certificates can carry https://3dwarden.com/verify/<public_id> directly.
For certificates already printed, keep your existing verification URL working. Resolve your own
token first, then redirect to the Warden address if you have a public_id stored for that member.
Keep your own page as the fallback. Do not send your verification tokens to Warden. It has no use
for them.