Diagnostics for the issues admins actually hit, in the order they usually hit them.
Pass URLs not generating
Check the debug logs for the NAMED_CREDENTIAL_RESPONSE status:
- Status 401 (Unauthorized) — the named credential password is wrong or the integration user was reset. Fix: Setup → Named Credentials → Kemicard_App → re-enter username/password.
- Status 409 (Conflict) — provisioning mismatch. Verify the Org ID matches what was provisioned; contact support to re-align licensing.
- Also confirm the org allows outbound email and the Configuration's email settings are set.
Org ID changed (sandbox refresh / migration)
A sandbox refresh or org migration changes the Org ID, so backend provisioning no longer matches and the integration user can show as disabled or .invalid. Fix: re-provision with the new Org ID and reauthorize the app.
Pass installs on Google but not Apple
If the org was re-provisioned or reauthorized, the integration may have picked up a default certificate instead of your client certificate. Symptom: Google Wallet works, Apple install fails. Fix: support re-aligns provisioning to your certificate; then test both platforms on device.
Cards moved to “expired” unexpectedly
- Apple relevant-date archive behavior — event passes older than a year with no relevant date may auto-archive. Push any update to restore the card; set relevant dates going forward.
- Wrong expiry data — trace the upstream pipeline (forms, batch imports, manual entry) before suspecting the package.
Google pass fields not rendering
Usually related to image module placement when secure images are enabled, or an outdated package version. Fix: upgrade to the latest package (v2.28 contained Google rendering fixes), then compare before/after payloads and escalate to support if fields still differ.
Enrollment emails not arriving
- Sandbox/scratch orgs with unverified domains won't send — enable the substitute-address option in Email Deliverability or provision DKIM for the sandbox.
- Trial emails are sometimes quarantined by client mail filters — check quarantine, then resend from an alternate domain.
- Verify an email template is set on the Configuration (required for Campaign Manager too).
Campaign Manager failing
- Immediate error — missing email template on Configuration. Set it, test with a one-record report, retry.
- “Too many SOQL queries” — legacy Process Builders firing on the same objects. Rebuild that logic into the Flow and deactivate the PB.
Scanner won't read a barcode
Check the format: QR and PDF417 are reliable; Code-128 is not reliably recognized. Regenerate the template with QR if needed.
Member shared their pass / duplicate installs
Since v2.29 this is a template setting rather than a workaround. Set it in Kemicard Studio under Preview → Back Side → share icon, separately for each wallet — see the sharing controls guide.
- Google Wallet — pick the level that matches the risk: Single User (Multiple Devices) ties the pass to the first Google account that saves it, Single User (Single Device) allows one installation on one device, and Sharing Prohibited stops anything else adding it. Forwarding the link then achieves nothing.
- Apple Wallet — turning Allow Sharing off removes the Share button from the pass. It does not block installation: a pass forwarded as an AirDropped file or an emailed link can still be added. That is Apple's platform behaviour, not a Kemicard limit, so treat the Apple switch as friction rather than a lock.
- Set the Google level before you distribute. Google only allows it to change while no member has saved the pass. Once a pass is in a wallet the level is locked.
- The barcode is a separate problem from the pass. If what you actually fear is a screenshot of the code rather than a forwarded pass, enable the rotating barcode — the photo stops working within seconds.
- Still useful alongside: disable the distribution link after install, or switch duplicated cards to a “duplicated card detected” error-state template.
Scanner keeps asking me to choose a camera
Pick Camera or External scanner on the Ready to check in screen — from v2.29 the choice is remembered on that device and browser. If it forgets between sessions, the browser is probably clearing site data on close; allow this site to keep its data.
External scanner isn't triggering a scan
Make sure the scanner is connected and set to keyboard (HID) mode, then click into the Waiting for a scan page so it has focus and pull the trigger. As a fallback, use Type a code instead to enter the code by hand.
Camera won't start, or the preview is dark
Allow camera access when the browser asks. In the Salesforce mobile app on iOS, tap Allow on the first prompt. If the camera idles and goes dark, reopen the scanner to restart it.
If the preview works but shows the attendant rather than the guest, the browser has picked a front-facing lens. Tap the camera label at the top of the scan view and choose one marked facing back — handsets commonly list four, and the default is not reliably the rear one.

Member's photo isn't showing on the scan result
The scanner flow needs the thumbnail or image field added to its result — it is not shown by default. Ask your Kemicard admin to include it; see Confirm identity and open links. If a link on the result is not clickable, the field has to be output as a URL (or Avatar/image) in the flow for it to be tappable.
Rotating barcode isn't changing, or a pass is rejected at the door
Confirm the Google Rotating Barcode toggle is on and the template was saved, then have the member re-add or refresh the Google pass; watch it for one full Period (Secs) before concluding anything. If a pass is rejected, check which wallet is being scanned — rotating barcodes are Google Wallet only, and the Apple version of the same pass keeps its standard barcode.
Still stuck?
Email supportkemisoft.com with the org ID, pass record ID, debug log excerpt, and screenshots. Enterprise tiers include priority investigation; deeper implementation work is scoped as a services engagement.
Geofence notification not appearing
- Confirm the template has 10 or fewer locations and coordinates are valid (re-geocode the address if it was entered before a move).
- Lock-screen surfacing requires the pass to be installed and the phone's location services enabled for Wallet.
- Known OS-level geofencing regressions exist on some iOS versions — validate on a second device before raising a ticket. Geofencing is supported on both Apple Wallet and Google Wallet, so a failure on one platform only is worth reporting rather than assuming.
Push notification not showing
- Apple suppresses a push whose text is identical to the previous one — change the message text.
- If Apple Wallet was open on the device, the message renders on the back of the card instead of as a banner.
- Confirm the pass is still installed (check the install status on the pass record) — removed passes receive nothing.
- Notifications require the device to be online; queued messages deliver on reconnect.
"Template limit reached" when creating a template
Template count per org is a licensing control. Delete unused draft templates, or contact your account manager to raise the limit on your plan.
Builder preview shows "(empty)" values
The live preview is driven by a sample record. Pick a sample record that has every mapped field populated, or set fallback values in the template's formatting rules.


