Skip to content

Ruby on Rails / certificates

Certificate PDFs in Ruby on Rails

Post your certificate HTML to a render API from a controller action using send_data, then send_data with type: "application/pdf". No browser binary in your Ruby on Rails deployment.

Why certificates become PDFs

A certificate is meant to be shown to a third party who has no relationship with the issuing system, and often printed. A link that could rot is not a credential. That is the difference between a document and a view of a database, and it is why training providers, course platforms and event organisers keep asking for this.

What a certificate has to carry

Before any of the code below matters, the template has to produce a document that is actually a certificate. These are the fields that make it one, and the ones a reader or an auditor will look for first.

  • the recipient full name exactly as they gave it
  • the achievement, named precisely enough to be checked
  • the issue date, and an expiry where the credential lapses
  • a unique certificate ID that a verifier can look up
  • the issuing body and an authorised signature or seal

Turning your ERB template into a document

You already have the markup. Render_to_string(template: "invoices/pdf", layout: false) gives you it as a string, which is the only input the render needs. stylesheet_link_tag emits a digested path like /assets/application-9a2f.css, which only exists on your host. For a renderer that does not share your origin, either inline the stylesheet with Rails.application.assets or point at an absolute URL on a public CDN.

The Ruby on Rails implementation

Net::HTTP ships with the runtime, so this adds no dependency. The render happens in a controller action using send_data, and you send_data with type: "application/pdf".

ruby

# app/controllers/certificates_controller.rb
require "net/http"

class CertificatesController < ApplicationController
  def pdf
    certificate = Certificate.find(params[:id])

    # layout: false is not optional. Without it the application layout wraps the
    # document and your site navigation prints across the top of page one.
    html = render_to_string(
      template: "certificates/pdf",
      layout: false,
      assigns: { certificate: certificate },
    )

    uri = URI("https://api.pdfpipe.xyz/v1/pdf")
    request = Net::HTTP::Post.new(uri)
    request["Authorization"] = "Bearer #{Rails.application.credentials.pdfpipe_key}"
    request["Content-Type"] = "application/json"
    request.body = {
      html: html,
      options: { format: "A4", printBackground: true },
    }.to_json

    upstream = Net::HTTP.start(uri.host, uri.port, use_ssl: true, read_timeout: 60) do |http|
      http.request(request)
    end

    # ASCII-8BIT, and it must stay that way. Anything that assumes UTF-8 here
    # corrupts the file with no error to explain it.
    send_data upstream.body,
              filename: "certificate-#{certificate.reference}.pdf",
              type: "application/pdf",
              disposition: "attachment"
  end
end

The CSS that makes a certificate page correctly

The layout problem specific to this document is that the design is fixed and usually landscape, so it must fit exactly one page regardless of how long the recipient's name is. These rules handle it.

css

/* Exactly one landscape page, whatever the name's length. */
@page {
  size: A4 landscape;
  margin: 0;
}

.certificate {
  width: 297mm;
  height: 210mm;
  break-after: avoid;
  display: grid;
  place-items: center;
}

/* Long names shrink rather than wrap onto a second line. */
.recipient {
  font-size: clamp(28px, 5vw, 54px);
  text-wrap: balance;
}

What goes wrong in Ruby on Rails

Forgetting layout: false is the single most common mistake here. Without it the application layout wraps the document, and the PDF arrives with your site navigation printed across the top of page one.

What people try first

Most Ruby on Rails projects reach for wicked_pdf, which shells out to wkhtmltopdf, or Prawn, which is excellent but means describing the document in Ruby drawing calls rather than in HTML you already have. That works until it is running on more than one machine, at which point the browser becomes the thing you operate rather than the thing you use.

Where the certificate lives afterwards

Rendering is the short part. The recipient keeps it indefinitely and may present it years later to an employer who will want to verify it. That is the argument for the ID field: the PDF is the artefact, but the ID is what makes it checkable after your system has changed.

Getting the document right

  • Check the recipient's name, which must render correctly for every alphabet your learners actually use.
  • Generation is triggered by a course or assessment being completed, so size the timeout for that path rather than for a health check.
  • Volume arrives in bursts, so queue the render rather than doing it inside the request that triggered it.
  • Backgrounds are painted by default here, so a design that uses colour needs nothing set. Only an explicit print_background of false turns them off.

Frequently asked

Do I need Chromium installed to generate certificates from Ruby on Rails?

No. The render happens over HTTP, so your Ruby on Rails deployment stays the size it is now. That is the main reason to use an API rather than wicked_pdf, which shells out to wkhtmltopdf, or Prawn, which is excellent but means describing the document in Ruby drawing calls rather than in HTML you already have.

How do I stop a long certificate using all the memory?

Send_data with type: "application/pdf". Forgetting layout: false is the single most common mistake here. Without it the application layout wraps the document, and the PDF arrives with your site navigation printed across the top of page one.

What has to be on a certificate?

At minimum: the recipient full name exactly as they gave it; the achievement, named precisely enough to be checked; the issue date, and an expiry where the credential lapses. The one to get right before anything else is the recipient's name, which must render correctly for every alphabet your learners actually use.

Do I need to store the generated certificates?

Depends on the document, and this one has a clear answer: the recipient keeps it indefinitely and may present it years later to an employer who will want to verify it. That is the argument for the ID field: the PDF is the artefact, but the ID is what makes it checkable after your system has changed.

Can I keep my existing certificate template?

Yes, if it produces HTML. Whatever renders your certificate view today can render the same markup for the PDF, which is why the CSS above is the only new thing you write.

Related

Other Ruby on Rails documents, and the same certificate in other stacks.

Statement PDFs in Ruby on Railsa statement summarises a period that is now closed. Regenerating it later from live data would produce a different documentQuote PDFs in Ruby on Railsa quote is an offer with an expiryPurchase order PDFs in Ruby on Railsa purchase order is the document a supplier's accounts team matches an invoice againstPayslip PDFs in Ruby on Railsa payslip is a personal financial record an employee keepsContract PDFs in Ruby on Railsa contract has to be fixed at signature. Both parties need to be certain they are looking at identical wordsCertificate PDFs in ExpressUsing fetch, in a route handler that pipes the response.Certificate PDFs in NestJSUsing fetch, or HttpService if you already inject it, in a controller returning StreamableFile.Certificate PDFs in Next.jsUsing fetch, in a Route Handler returning a Response.Certificate PDFs in Spring BootUsing java.net.http.HttpClient, in a controller returning StreamingResponseBody.Certificate PDFs in ASP.NET CoreUsing IHttpClientFactory, in an action returning FileStreamResult.The same thing in plain RubyWithout the framework, using Net::HTTP directly.When the output is wrongBlank pages, missing backgrounds, breaks in the wrong place, by symptom.All stacks and documentsThe full grid of what this covers.the full Ruby on Rails guideSetup, error handling and the deployment shape, not just the request.certificate generation in productionVolume, storage and the delivery step, for teams already shipping these.how this compares to wicked-pdfThe tradeoff written out, including where the incumbent is the better call.migrating off another rendererWhat changes in the output when you switch, and what to check first.

100 free documents a month, no card.