PDFPipe

ASP.NET Core / certificates

Certificate PDFs in ASP.NET Core

Post your certificate HTML to a render API from an action returning FileStreamResult, then return File(stream, "application/pdf"). No browser binary in your ASP.NET Core deployment.

Why certificates become PDFs

A certificate is meant to be shown to a third party who has no relationship with the issuing system, and often printed. A link that could rot is not a credential. That is the difference between a document and a view of a database, and it is why training providers, course platforms and event organisers keep asking for this.

What a certificate has to carry

Before any of the code below matters, the template has to produce a document that is actually a certificate. These are the fields that make it one, and the ones a reader or an auditor will look for first.

  • the recipient full name exactly as they gave it
  • the achievement, named precisely enough to be checked
  • the issue date, and an expiry where the credential lapses
  • a unique certificate ID that a verifier can look up
  • the issuing body and an authorised signature or seal

Turning your Razor template into a document

You already have the markup. Await _razorRenderer.RenderViewToStringAsync("Invoice", model) gives you it as a string, which is the only input the render needs. Rendering a Razor view to a string outside the MVC pipeline needs an explicit ActionContext, which is why most projects end up with a small RazorViewToStringRenderer service. Write it once and inject it.

The ASP.NET Core implementation

IHttpClientFactory ships with the runtime, so this adds no dependency. The render happens in an action returning FileStreamResult, and you return File(stream, "application/pdf").

csharp
// Controllers/CertificateController.cs
using System.Net.Http.Json;

[ApiController]
public class CertificateController : ControllerBase
{
    private readonly IHttpClientFactory _factory;
    private readonly RazorViewToStringRenderer _razor;

    public CertificateController(IHttpClientFactory factory, RazorViewToStringRenderer razor)
        => (_factory, _razor) = (factory, razor);

    [HttpGet("/certificates/{id}.pdf")]
    public async Task<IActionResult> Pdf(string id, CancellationToken ct)
    {
        var certificate = await _certificates.FindAsync(id, ct);
        var html = await _razor.RenderViewToStringAsync("CertificatePdf", certificate);

        // From the factory. new HttpClient() per request exhausts sockets under
        // load, and the symptom only appears in production.
        var client = _factory.CreateClient("pdfpipe");

        var upstream = await client.PostAsJsonAsync("https://api.pdfpipe.xyz/v1/pdf", new
        {
            html,
            options = new { format = "A4", printBackground = true },
        }, ct);

        upstream.EnsureSuccessStatusCode();

        var stream = await upstream.Content.ReadAsStreamAsync(ct);
        return File(stream, "application/pdf", $"certificate-{id}.pdf");
    }
}

The CSS that makes a certificate page correctly

The layout problem specific to this document is that the design is fixed and usually landscape, so it must fit exactly one page regardless of how long the recipient's name is. These rules handle it.

css
/* Exactly one landscape page, whatever the name's length. */
@page {
  size: A4 landscape;
  margin: 0;
}

.certificate {
  width: 297mm;
  height: 210mm;
  break-after: avoid;
  display: grid;
  place-items: center;
}

/* Long names shrink rather than wrap onto a second line. */
.recipient {
  font-size: clamp(28px, 5vw, 54px);
  text-wrap: balance;
}

What goes wrong in ASP.NET Core

new HttpClient() per request exhausts sockets under sustained load, because each disposed handler leaves a connection in TIME_WAIT. Inject IHttpClientFactory. This is the most common .NET HTTP mistake that only appears in production.

What people try first

Most ASP.NET Core projects reach for PuppeteerSharp, which downloads and supervises a Chromium build from inside your own process, or QuestPDF, which is a fluent layout API rather than a way to render HTML you already have. That works until it is running on more than one machine, at which point the browser becomes the thing you operate rather than the thing you use.

Where the certificate lives afterwards

Rendering is the short part. The recipient keeps it indefinitely and may present it years later to an employer who will want to verify it. That is the argument for the ID field: the PDF is the artefact, but the ID is what makes it checkable after your system has changed.

Getting the document right

  • Check the recipient's name, which must render correctly for every alphabet your learners actually use.
  • Generation is triggered by a course or assessment being completed, so size the timeout for that path rather than for a health check.
  • Volume arrives in bursts, so queue the render rather than doing it inside the request that triggered it.
  • Backgrounds are painted by default here, so a design that uses colour needs nothing set. Only an explicit print_background of false turns them off.

Frequently asked

Do I need Chromium installed to generate certificates from ASP.NET Core?

No. The render happens over HTTP, so your ASP.NET Core deployment stays the size it is now. That is the main reason to use an API rather than PuppeteerSharp, which downloads and supervises a Chromium build from inside your own process, or QuestPDF, which is a fluent layout API rather than a way to render HTML you already have.

How do I stop a long certificate using all the memory?

Return File(stream, "application/pdf"). new HttpClient() per request exhausts sockets under sustained load, because each disposed handler leaves a connection in TIME_WAIT. Inject IHttpClientFactory. This is the most common .NET HTTP mistake that only appears in production.

What has to be on a certificate?

At minimum: the recipient full name exactly as they gave it; the achievement, named precisely enough to be checked; the issue date, and an expiry where the credential lapses. The one to get right before anything else is the recipient's name, which must render correctly for every alphabet your learners actually use.

Do I need to store the generated certificates?

Depends on the document, and this one has a clear answer: the recipient keeps it indefinitely and may present it years later to an employer who will want to verify it. That is the argument for the ID field: the PDF is the artefact, but the ID is what makes it checkable after your system has changed.

Can I keep my existing certificate template?

Yes, if it produces HTML. Whatever renders your certificate view today can render the same markup for the PDF, which is why the CSS above is the only new thing you write.

Related

Other ASP.NET Core documents, and the same certificate in other stacks.

100 free documents a month, no card.