← All posts

How serialised codes work, and why we never keep a list of them

A code on a pack is worth money, so three things could go wrong: someone guesses one, someone steals the list, or one gets used twice. Each has an answer.

12 September 20263 min read

Printing a unique code on a pack is printing a small bearer instrument. Whoever reads it can claim the money behind it. That is a strange thing to send into a supply chain, and it only works if three specific problems are solved.

Problem one: guessing

If codes are sequential — 000001, 000002 — then one pack tells you every other pack. So codes are random, drawn from a space far too large to work through by hand or by script, and they are checked against a rate limit that notices somebody trying.

Randomness alone is not enough, though, because a shopper has to type the thing. The format does two jobs at once:

  • It leaves out the letters that look like digits. No I, no L, no O. If a shopper types one anyway, it is quietly read as the digit it resembles, so their mistake just works.
  • It carries a check character. Mistype one character and the code fails as a typo rather than landing on somebody else's valid code — which is the failure that would actually cost money.
  • It is grouped in threes, because that is how people read and copy strings without losing their place.

Problem two: the list

Every promotion that has ever leaked did so because somebody had the list: an agency, a printer, a database backup, an employee with an export. The only real defence is not to have one.

So after a print run is generated, the readable codes exist for 30 days — long enough to get a file to the printer — and are then destroyed. What remains is a fingerprint of each code: enough to recognise one when a shopper sends it in, not enough to reproduce it.

A breach two years from now exposes nothing worth stealing, because by then the codes are not there to steal.

The codes on shelves keep working forever. We simply cannot read them out ourselves any more, and neither can anyone who gets into our database.

Problem three: reuse

A code pays exactly once. The second attempt is refused — and, more usefully, counted.

That counter is the part brands underestimate. Repeat attempts are tallied against the print run they came from, so an unusual number of them is a signal with an address: this run, this product, this window. It may be copied packs, a photographed code circulating in a WhatsApp group, or a file that went somewhere it should not have. You cannot act on what you cannot see, and until now a brand could not see it at all.

Where the code sits on the pack

There is one more problem, and it is not cryptographic. A code printed on the outside of a pack can be read by anyone standing in the aisle, and a promotion whose rewards can be claimed without buying is not a promotion — it is a bowl of sweets by the door.

So the code goes inside: under the cap, inside a flap, on an insert card. The QR that starts the conversation stays on the outside, where a camera can reach it, and carries no secret at all — it is the same on every pack of that product.

For a pack with no inside, like a sachet, the choice is honest rather than clever: print a unique QR on each one and accept that it is reachable on the shelf, or put the code under a scratch panel if the budget allows.

Why a brand should care about any of this

Because the alternative is finding out the expensive way. Every one of these decisions was made to protect the same promise: that the shopper who bought your pack, in good faith, gets paid — and that nobody else does.

Give them a reason to pick yours.

Jireward puts a code inside every pack and pays whoever buys it, on WhatsApp, in airtime or M-Pesa.