Free boarding pass generator

Build a synthetic IATA BCBP barcode and download a boarding pass image to test a boarding pass scanner.

For testing only. Every value on this page is randomly generated sample data and each pass is stamped SPECIMEN. No live reservation system is involved. The output is not a valid travel document, will not pass an airport check, and must not be used to travel or to impersonate anyone. Use it to test a scanner.

Pass setup

A printed pass uses PDF417, which is what Resolution 792 originally specified. Version 7 opened the same payload up to Aztec Code, QR Code and Data Matrix for mobile and 2D printed passes, so choosing one of those raises the version to 7.

Passenger

The passenger name is written as SURNAME/GIVEN NAME and left-justified in 20 characters. A baggage tag is 13 digits: a 10-digit licence plate followed by a 3-digit count of consecutive bags. The first three tags fill item 23; a fourth and fifth become the non-consecutive items 31 and 32.

Optional data (the conditional sections)

BCBP has no field tags: the optional items are written in a fixed order and only the trailing ones may be dropped. Leaving an early field empty while filling a later one is therefore not expressible, and the validator reports it instead of quietly padding a gap with filler. The last optional block — the security section — sits in its own card below, because you never fill it in yourself.

Security data (items 25–30) — optional, signed for you

Signing… item 30 is filled in for you after every change.

You are not meant to work this value out — it is a signature over the payload, produced automatically whenever any other field changes. It is written once, after the last leg: ^ (item 25), the type (item 28), the length in two hexadecimal characters (item 29), then the base64 signature itself. Edit the field by hand to build a pass that fails verification, clear it to omit the section entirely, or press Re-sign to put a valid signature back.

Flight legs

Pass preview

Auto-generated — the barcode redraws itself as soon as any value changes.

You do not need to press anything: edit a field, add or remove a leg, or hit Randomise and this pass is rebuilt and re-rendered automatically.

Generating…

Encoded BCBP payload

This is the exact string the barcode encodes. Positions 1–23 are the unique mandatory section, 24–58 the repeated section, then the two hexadecimal characters of item 6 and the leg's variable field. Every leg repeats the 35-character block plus its own size field, so a two-leg pass is longer than twice a one-leg pass.

Expected scanner output

Read this table back as the test oracle: it is produced by parsing the payload that was just generated, so it states what the bytes contain, not what the form says. The offset column is the 1-based position of the field in the payload, which is what makes a mismatch with a scanner easy to localise.

Scope and limitations

This generator implements the linear data layout of IATA Resolution 792 — the payload a scanner reads out of the symbol. A BCBP payload is plain text, so a well-formed pass proves only that the data is well formed. This page does sign its output with a demo key so you can watch items 25–30 being written and checked, but that proves only that this page produced the bytes: a parseable boarding pass is never evidence that a passenger holds a real reservation.

The security section is signed for you, not typed. Items 25–30 are written once, after the last leg: ^ (item 25), one character of type (item 28), two hexadecimal characters of length (item 29), then the data. Whenever a field changes, the whole payload up to the end of the last leg is signed with ECDSA P-256 and the 88-character base64 signature lands in item 30. The private key is baked into this page so the demo can sign in the browser — something a real issuer must never do: that key stays on the issuing server, only the signature travels, and readers get the matching public key, which is what the scanner example carries. Clear the field to see the other case: an unsigned pass is legal and still reads, and is only refused by a reader that has been told to require a signature.

Aztec, QR Code and Data Matrix are only standard for a printed pass from version 7 onwards. Older readers may accept the symbol but expect PDF417, which is why PDF417 remains the safe choice for a printed pass and the default here.

The flight date carries no year. BCBP stores a Julian day of the year, so a scanner has to infer the year from the issue date or from the current date. A pass issued at the turn of the year can therefore be ambiguous through no fault of the data.

Airline names, numeric codes and airport cities come from a short built-in reference table so that sample data reads realistically. It is not an authoritative IATA dataset, and the decoded labels are for readability only.