API Reference
QRMax REST API v1 — OpenAPI 3.1 spec, JWT authentication, rate-limited by plan tier.
https://api.qrmax.io/api/v1Authentication
All requests require a Bearer token. Generate API keys from your Dashboard → Settings → API Keys page. Keys are scoped per workspace; rotate them anytime without breaking active QRs.
Rate limits
| Plan | Per-minute | Daily cap |
|---|---|---|
| Free | 20 req/min | 1,000 /day |
| Starter | 60 req/min | 10,000 /day |
| Pro | 120 req/min | 50,000 /day |
| Business | 300 req/min | 200,000 /day |
| Enterprise | 600+ req/min | Custom |
Rate limit headers returned on every response: X-RateLimit-Limit,X-RateLimit-Remaining,X-RateLimit-Reset.
Endpoints
/api/v1/qr-codesList QR codes
Returns a paginated list of QR codes in the current workspace. Supports filtering by type, campaign, and date range.
Request
curl https://api.qrmax.io/api/v1/qr-codes \
-H "Authorization: Bearer $QRMAX_API_KEY"Response
{
"data": [
{
"id": "qr_01HNPAXK...",
"type": "url",
"target": "https://example.com",
"scans": 1247,
"createdAt": "2026-04-01T10:23:00Z"
}
],
"page": 1,
"total": 1
}/api/v1/qr-codesCreate a QR code
Creates a new static or dynamic QR code. Dynamic codes return a short URL that can be re-targeted later.
Request
curl https://api.qrmax.io/api/v1/qr-codes \
-X POST \
-H "Authorization: Bearer $QRMAX_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"type": "url",
"target": "https://example.com/spring-sale",
"dynamic": true
}'Response
{
"id": "qr_01HNPAXK...",
"shortUrl": "https://qrx.io/a3b9c2",
"imageUrl": "https://cdn.qrmax.io/qr/qr_01HNPAXK.png",
"type": "url",
"target": "https://example.com/spring-sale",
"dynamic": true,
"createdAt": "2026-04-19T18:30:00Z"
}/api/v1/qr-codes/:idUpdate a dynamic QR code
Re-targets a dynamic QR code to a new destination. The printed code remains unchanged — only the redirect is updated.
Request
curl https://api.qrmax.io/api/v1/qr-codes/qr_01HNPAXK \
-X PATCH \
-H "Authorization: Bearer $QRMAX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"target": "https://example.com/summer-sale"}'Response
{
"id": "qr_01HNPAXK...",
"target": "https://example.com/summer-sale",
"updatedAt": "2026-04-19T18:45:22Z"
}/api/v1/qr-codes/:id/analyticsGet scan analytics
Returns scan counts, unique scanners, device/OS breakdown, and geo data for a specific QR code over a date range.
Request
curl "https://api.qrmax.io/api/v1/qr-codes/qr_01HNPAXK/analytics?from=2026-04-01&to=2026-04-19" \
-H "Authorization: Bearer $QRMAX_API_KEY"Response
{
"totalScans": 1247,
"uniqueScanners": 892,
"devices": { "ios": 512, "android": 680, "other": 55 },
"topCountries": [
{ "code": "US", "scans": 420 },
{ "code": "IN", "scans": 310 }
]
}/api/v1/qr-codes/:idDelete a QR code
Permanently deletes a QR code. Dynamic redirects stop working immediately. Historical analytics are retained for 90 days.
Request
curl -X DELETE https://api.qrmax.io/api/v1/qr-codes/qr_01HNPAXK \
-H "Authorization: Bearer $QRMAX_API_KEY"Response
{ "deleted": true, "id": "qr_01HNPAXK..." }Webhooks
Subscribe to events like qr.scanned, qr.created,campaign.ended, and subscription.updated. All payloads are signed with HMAC-SHA256 using your webhook secret.
Get an API key
Free plan includes 1,000 API calls/day. No credit card required.
Sign up for API access