PO Box 55056 RPO Windermere, Edmonton, AB T6W 5B4, Canada

Advanced Google Wallet Features

Three controls introduced in Kemicard v2.29: a rotating barcode that makes a screenshot useless within seconds, sharing rules that decide which wallets a pass may reach, and a private member photo that no longer forces a screen-lock prompt. Each is configured per template in Kemicard Studio, so different passes can carry different protections.

Why this release exists. A digital pass is only as controlled as the copies that get away from you. On most wallet systems the weak point is the screenshot: a photo of a static QR code keeps working long after the visit it was issued for, and one membership card quietly starts doing the work of two.

1. Rotating barcode — a code that expires in seconds

Rotating Barcode replaces the static QR code on a Google Wallet pass with one that refreshes every few seconds. Every pass issued from an enabled template carries its own secret, and the Kemicard Scanner validates the current code live at the door. A screenshot taken a minute earlier no longer matches anything.

What it doesWhy it matters
Replaces the static QR code with a code that refreshes on an interval you set.A screenshot of the pass goes stale almost immediately, so a captured image cannot be reused to get someone else through the door.

Where it lives

Kemicard Studio → Settings → Barcodes → Rotating Barcode (Google)

  1. Open your template in Kemicard Studio. Click the Kemicard Studio tab in the app's top navigation. If no template is open, go to Kemicard Templates, open your template, then click Open in Kemicard Studio. You will see a Settings panel on the left and a Preview on the right.
  2. Open the Barcodes settings. Click the Barcodes icon in the left icon rail. The panel shows Barcode Formats, Data Mapping, and the Rotating Barcode card.
  3. Turn the rotating barcode on. In the Rotating Barcode (Google) card, click the Google Rotating Barcode switch so it reads Enabled. Two fields appear.
  4. Set how often the code refreshes. In Period (Secs), type the refresh interval — default 20 seconds, allowed 5–600.
  5. Set the code length. In Digits Length, type the number of digits — default 6, allowed 6–8.
  6. Save. Click Save at the bottom of the Settings panel. The Google preview updates to show the rotating QR code.
The Rotating Barcode (Google) card in Kemicard Studio with the toggle enabled and Period and Digits Length fields
Settings → Barcodes: the Rotating Barcode (Google) card, toggled on with Period and Digits Length.
Kemicard Studio showing the rotating barcode settings on the left and the live Apple and Google pass previews on the right
The setting and its effect side by side — the Google preview picks up the rotating code as soon as you save.

Field reference

SettingWhat it controlsDefaultRange
Google Rotating BarcodeTurns the rotating (dynamic) barcode on or off for this template.OffOn / Off
Period (Secs)How often the barcode refreshes to a new value.20 sec5–600
Digits LengthNumber of digits in each rotating code.66–8
Google Wallet only. Rotating barcodes apply to the Google Wallet version of the pass. The Apple Wallet version keeps its standard barcode, so your door staff need to scan the Google pass for the anti-fraud coverage to apply.
Pick a comfortable window. A shorter period (15–20 seconds) is harder to share but needs a steady connection at the door. A longer one is more forgiving in venues with weak signal. Choose for the venue, not for the threat model in the abstract.

2. Pass sharing controls — decide which wallets a pass may reach

Not every pass should travel. v2.29 turns that decision into a template setting, handled separately for each wallet — so you can restrict one platform without touching the other.

Sharing is configured on the back of the pass in the Preview panel.

Getting to the sharing settings

Kemicard Studio → Preview → Back Side → share icon

  1. Open the template in Kemicard Studio so the Preview panel shows on the right.
  2. In the Preview panel, click the Back Side tab.
  3. Each pass card has a share icon in its top-right corner. Click it on the Apple card to open Apple's settings, or on the Google card to open Google's.
The Back Side preview in Kemicard Studio with a share icon in the top-right corner of each pass card
Each pass card in the Back Side preview carries a share icon — click it to open that wallet's sharing settings.

Apple Wallet — on or off

Apple sharing is a single switch. In Apple Pass Sharing Settings, turn Allow Sharing off to restrict it — the Share option then will not appear when the member views the pass. Click Save.

The Apple Pass Sharing Settings dialog with the Allow Sharing switch
Apple Pass Sharing Settings — one switch, shown here in the enabled state.
Apple hides the button, not the pass. Turning Apple sharing off removes the Share button from the pass. It does not block installation: a pass forwarded another way — an AirDropped file, an emailed link — can still be added to a wallet. That behaviour comes from Apple's platform, not from a limit inside Kemicard. If you need the pass itself locked to one holder, use Google's levels below, or pair the Apple pass with a rotating-barcode Google pass at the door.

Google Wallet — four levels

Google gives finer control. In Google Pass Sharing Settings, choose one of the four levels and click Save.

The Google Pass Sharing Settings dialog listing Fully Shareable, Single User Multiple Devices, Single User Single Device and Sharing Prohibited
Google Pass Sharing Settings — from Fully Shareable down to Sharing Prohibited.
LevelGoogle valueWhat it doesBest for
Fully Shareable (default)MULTIPLE_HOLDERSAnyone with the link can add this pass to their Google Wallet, on any device.Public events, coupons, general store cards.
Single User (Multiple Devices)ONE_USER_ALL_DEVICESLocks to the first Google account that saves it. Forwarding the link achieves nothing, but the holder can install it on several of their own devices.Personal memberships used on a phone and a smartwatch.
Single User (Single Device)ONE_USER_ONE_DEVICEMost restrictive — a single installation on a single physical device, no exceptions.Secure transit tickets, boarding passes.
Sharing ProhibitedSharing is off. The pass links to the first Google account that adds it; nothing else can add it.IDs and tickets that must never circulate.
The Google Pass Sharing Settings dialog with Sharing Prohibited turned on
Sharing Prohibited, switched on. The four levels make it easy to match the restriction to the risk.
Set Google sharing before you distribute. Google only permits the sharing level to change while no member has saved the pass. Once a pass is in a wallet the level is locked and the builder reports that passes have already been generated and saved. This is the one setting on this page you cannot revisit later, so decide it first.
Apple and Google are independent. You can restrict one wallet and leave the other open. A coupon can stay fully shareable, a transit pass can be locked to one device, and an ID can prohibit sharing outright — all from the same template set.

3. Private Image — a member photo without the screen-lock prompt

A member photo is the fastest identity check a door attendant has. Until this release, showing a private image on a Google Wallet pass required a Secure Pass, and a Secure Pass asks the member to unlock the phone before the image appears — which is a real cost when someone is holding up a queue.

The new Private Image type shows the photo on a standard pass. The image stays private to the pass holder, and no unlock prompt appears. Where screen-lock verification genuinely is wanted, Secure Private Image remains available as a separate option.

Kemicard Studio → Google → Type → Private Image

  1. In Kemicard Studio, open your template and go to the Google configuration, where the pass Type is chosen.
  2. Set the Google type to Private Image. Choose Secure Private Image only if you specifically want to require screen-lock verification before the photo shows.
  3. Point it at the photo — set the image field to the source you want on the pass, for example the member's photo field on the record.
  4. Click Save, then check the Google preview. The private image appears on a standard pass.
Apple and Google pass previews in Kemicard Studio, both showing a member photo alongside the member number and QR code
The member photo rendered on the pass. The green outline on the Google QR marks the rotating barcode; the padlock marks the private image.
Google typeMember experienceWhen to use
Private Image (new in v2.29)Photo shows on a standard pass — no unlock prompt.Member photos, ID badges, everyday membership cards.
Secure Private ImageMembers must unlock the phone (biometric or screen-lock) to view.Sensitive content that should be gated behind device unlock.
The image stays private either way. Both options keep the image private to the pass holder. The difference is only whether the member is asked to unlock the phone before it is shown.

Choosing between the three

They solve different halves of the same problem, and they compose:

The riskThe control
Someone photographs the barcode and sends the photo onRotating barcode — the photo stops working within seconds
Someone forwards the pass itself to another walletSharing controls — Google can refuse the second install outright
The person at the door is not the person the pass was issued toPrivate Image plus a scanner flow that shows the photo on the result

For a high-value credential — a staff badge, a season ticket, a transit pass — all three together mean the barcode expires, the pass cannot be re-installed elsewhere, and the attendant can see whose face should be in front of them. The Scanner & Check-In guide covers the last of those.

Troubleshooting

Confirm the Google Rotating Barcode toggle is on and the template was saved, then have the member re-add or refresh the Google pass. The code refreshes on the interval set in Period (Secs) — watch it for one full period before concluding anything.

For rotating-barcode passes, scan the member's Google Wallet pass, not the Apple one. Only the Google pass carries the live rotating code, so scanning the Apple pass will not validate against it.

Google only allows the sharing level to change while no member has saved the pass. Once a pass is in a wallet, Google locks it and the builder shows a “passes have already been generated and saved” message. Set sharing before distributing.

Open the pass's Google sharing settings and choose Fully Shareable (or another level), then save. Existing passes update on their next refresh.

That is the behaviour of Secure Private Image. Switch the Google type to Private Image to show the photo without a screen-lock prompt.

Template changes apply to newly issued passes right away. Passes already in a wallet update when the wallet refreshes them, which can take a little time.

Ready to lock down your passes?

All three controls are configured per template in Kemicard Studio and are available now in v2.29.