Skip to content
REST API v1

QR Code API for Dynamic QR Codes and Short Links

The Qdestera QR code API lets your software do what your team does in the dashboard. Create dynamic URL QR codes and short links, update destinations, switch codes on or off and download QR images – with scoped API keys and signed webhooks for every scan.

  • REST API with an OpenAPI document
  • API keys with scopes and optional expiry
  • Scan webhooks signed with HMAC-SHA256

What you can do with the QR code API

Version 1 of the API covers the everyday work around dynamic QR codes and short links.

The API is a plain REST interface that speaks JSON over HTTPS. Every request is made with an API key that belongs to one workspace, so an integration only ever sees that workspace's codes and links.

  • QR codes: list (with search, status filter and paging), get, create dynamic URL QR codes, update, activate or deactivate, delete
  • QR images: download the rendered PNG of a code
  • Short links: list, get, create, update, activate or deactivate, delete
  • Scan webhooks: receive a signed HTTP call on every scan

QR code API endpoints at a glance

Read operations need a read scope; everything that changes data needs a write scope.

Operation QR codes Short links
List with paging Yes Yes
Get one by id Yes Yes
Create ✓ (dynamic URL) Yes
Update destination and details Yes Yes
Activate or deactivate Yes Yes
Delete Yes Yes
Download image ✓ (PNG) No
Scopes qr:read, qr:write link:read, link:write

How to get started

  1. Create an API key

    In your dashboard, create a key for one integration. Give it only the scopes it needs – qr:read, qr:write, link:read or link:write – and optionally an expiry date.

  2. Open the OpenAPI document

    While signed in, load the OpenAPI document for version 1 into your API client or code generator. It describes every endpoint, parameter and response.

  3. Send your first request

    Send the key in a request header and call an endpoint, for example GET /api/v1/qrcodes to list your codes. Responses are JSON.

  4. Stay within the rate limit

    Each key has a per-plan rate limit. If you exceed it, the API answers with HTTP 429 and a Retry-After header, so your client knows when to try again.

Example: a QR code for every new product

Imagine your shop system adds a product and needs a QR code for its label. First it calls POST /api/v1/links to create a short link that points to the product page. Then it calls POST /api/v1/qrcodes to create a dynamic URL QR code for that link, and GET /api/v1/qrcodes/{id}/image to fetch the PNG for the label printer.

Months later the product page moves. Your system sends one update request with the new destination, and every label already on the shelf opens the right page on the next scan. The exact request fields are listed in the OpenAPI document.

The same pattern works for tickets, certificates, packaging runs or product QR codes created in bulk: your system keeps the data, Qdestera keeps the codes working.

Built for real integrations

Scoped API keys

Create a separate key for each integration, limit it to read or write access for QR codes and links, and let it expire automatically when a project ends.

  • Scopes: qr:read, qr:write, link:read, link:write
  • Optional expiry date
  • Per-plan rate limits per key

Signed scan webhooks

Get an HTTP call on every scan of a single code, a folder or the whole workspace. Each request is signed with HMAC-SHA256 so you can verify it, failed deliveries are retried and a delivery log lists every delivery.

  • HMAC-SHA256 signature
  • Automatic retries
  • Delivery log in the dashboard

Teams, roles and an audit log

The people around the API work in the same workspace. Invite colleagues as Owner, Admin, Editor or Viewer, and keep track of changes in the audit log.

  • Four roles
  • Invitation links
  • Strict workspace isolation

Scan webhooks in more detail

Webhooks are part of scan automations. You choose the scope – one code, a folder or the whole workspace – and the endpoint that should receive the call. On every scan, Qdestera sends the event to your endpoint.

Each request carries an HMAC-SHA256 signature computed with a secret you share only with us. Recompute it on your side and reject anything that does not match. If your endpoint is down, delivery is retried, and the delivery log lists each delivery with its status. The same scans also appear in your QR code analytics.

What teams build with the API

Labels and packaging

Generate a code per product or batch straight from your ERP or shop system.

Agency tools

Marketing agencies create and manage client codes from their own campaign tools.

CRM and alerts

Turn a scan into a CRM activity, a chat message or a row in your reporting database.

Internal dashboards

Pull codes and links into the tools your team already uses every day.

Best practices for the QR code API

  • One key per integration

    Separate keys make it easy to rotate or revoke one integration without touching the others.

  • Least privilege

    A reporting script only needs read scopes. Give write scopes only to systems that create or change codes.

  • Keep keys on the server

    Never put an API key in a mobile app, a browser script or a public repository.

  • Verify every webhook

    Check the HMAC-SHA256 signature before you trust the content of a webhook request.

  • Respect Retry-After

    When you receive HTTP 429, wait for the time given in the Retry-After header before retrying.

  • Brand the links

    Create links on your custom domain so API-generated codes carry your name too.

API key security

API keys are stored as hashes, not in plain text, and each key only works for the workspace that created it. The dashboard shows when a key was last used, so forgotten integrations are easy to spot.

If a key may have leaked, rotate it to get a new secret or revoke it to switch it off immediately. Creating keys is recorded in the workspace audit log, so admins can see who set up which integration.

Build your first integration

Create an account, generate an API key with the scopes you need and send your first request.

Get an API key
FAQ

Frequently asked questions

Still have a question? Read our guides or contact us .

Is there a REST API for creating QR codes?

Yes. Version 1 of the Qdestera REST API lets you create dynamic URL QR codes and short links, and list, update, activate, deactivate and delete them.

How do I authenticate with the API?

Create an API key in your dashboard and send it with each request in a header. Each key belongs to one workspace and has its own scopes.

What scopes do API keys have?

qr:read, qr:write, link:read and link:write. You can combine them and give a key an optional expiry date.

Are there rate limits?

Yes, per key and depending on your plan. When a key exceeds its limit, the API returns HTTP 429 with a Retry-After header.

Can I download the QR code image through the API?

Yes. Request the image of a QR code by its id and you receive the rendered PNG.

Is there an OpenAPI or Swagger document?

Yes. An OpenAPI document describes all version 1 endpoints; open it while signed in and import it into your API client.

Can the API notify me when a code is scanned?

Yes, through scan automations. A webhook is called on every scan, signed with HMAC-SHA256, with retries and a delivery log.

Which QR types can I create through the API?

Version 1 creates dynamic URL QR codes. Other types are created in the dashboard and can then be listed and managed through the API.

Can links created through the API use my custom domain?

Yes. When you create a short link, you can choose a custom domain that is verified and active in your workspace.

Can I rotate or revoke an API key?

Yes. Rotate a key to replace its secret, or revoke it to stop it from working at once. The dashboard also shows when each key was last used.

Qdestera

Automate your QR codes.

Scoped API keys, a documented REST API and signed webhooks – ready when your account is.

Start free