Back to docs

API Reference

QRMax REST API v1 — OpenAPI 3.1 spec, JWT authentication, rate-limited by plan tier.

Base URLhttps://api.qrmax.io/api/v1

Authentication

All requests require a Bearer token. Generate API keys from your Dashboard → Settings → API Keys page. Keys are scoped per workspace; rotate them anytime without breaking active QRs.

Authorization: Bearer qrmx_live_sk_•••••••••••••••
Never commit API keys. Use environment variables or a secret manager.

Rate limits

PlanPer-minuteDaily cap
Free20 req/min1,000 /day
Starter60 req/min10,000 /day
Pro120 req/min50,000 /day
Business300 req/min200,000 /day
Enterprise600+ req/minCustom

Rate limit headers returned on every response: X-RateLimit-Limit,X-RateLimit-Remaining,X-RateLimit-Reset.

Endpoints

GET/api/v1/qr-codes

List QR codes

Returns a paginated list of QR codes in the current workspace. Supports filtering by type, campaign, and date range.

Request

curl https://api.qrmax.io/api/v1/qr-codes \
  -H "Authorization: Bearer $QRMAX_API_KEY"

Response

{
  "data": [
    {
      "id": "qr_01HNPAXK...",
      "type": "url",
      "target": "https://example.com",
      "scans": 1247,
      "createdAt": "2026-04-01T10:23:00Z"
    }
  ],
  "page": 1,
  "total": 1
}
POST/api/v1/qr-codes

Create a QR code

Creates a new static or dynamic QR code. Dynamic codes return a short URL that can be re-targeted later.

Request

curl https://api.qrmax.io/api/v1/qr-codes \
  -X POST \
  -H "Authorization: Bearer $QRMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "url",
    "target": "https://example.com/spring-sale",
    "dynamic": true
  }'

Response

{
  "id": "qr_01HNPAXK...",
  "shortUrl": "https://qrx.io/a3b9c2",
  "imageUrl": "https://cdn.qrmax.io/qr/qr_01HNPAXK.png",
  "type": "url",
  "target": "https://example.com/spring-sale",
  "dynamic": true,
  "createdAt": "2026-04-19T18:30:00Z"
}
PATCH/api/v1/qr-codes/:id

Update a dynamic QR code

Re-targets a dynamic QR code to a new destination. The printed code remains unchanged — only the redirect is updated.

Request

curl https://api.qrmax.io/api/v1/qr-codes/qr_01HNPAXK \
  -X PATCH \
  -H "Authorization: Bearer $QRMAX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"target": "https://example.com/summer-sale"}'

Response

{
  "id": "qr_01HNPAXK...",
  "target": "https://example.com/summer-sale",
  "updatedAt": "2026-04-19T18:45:22Z"
}
GET/api/v1/qr-codes/:id/analytics

Get scan analytics

Returns scan counts, unique scanners, device/OS breakdown, and geo data for a specific QR code over a date range.

Request

curl "https://api.qrmax.io/api/v1/qr-codes/qr_01HNPAXK/analytics?from=2026-04-01&to=2026-04-19" \
  -H "Authorization: Bearer $QRMAX_API_KEY"

Response

{
  "totalScans": 1247,
  "uniqueScanners": 892,
  "devices": { "ios": 512, "android": 680, "other": 55 },
  "topCountries": [
    { "code": "US", "scans": 420 },
    { "code": "IN", "scans": 310 }
  ]
}
DELETE/api/v1/qr-codes/:id

Delete a QR code

Permanently deletes a QR code. Dynamic redirects stop working immediately. Historical analytics are retained for 90 days.

Request

curl -X DELETE https://api.qrmax.io/api/v1/qr-codes/qr_01HNPAXK \
  -H "Authorization: Bearer $QRMAX_API_KEY"

Response

{ "deleted": true, "id": "qr_01HNPAXK..." }

Webhooks

Subscribe to events like qr.scanned, qr.created,campaign.ended, and subscription.updated. All payloads are signed with HMAC-SHA256 using your webhook secret.

Browse webhook events

Get an API key

Free plan includes 1,000 API calls/day. No credit card required.

Sign up for API access