The QRCodeStack REST API lets you create, manage, and track dynamic QR codes and short links programmatically. Use it to integrate QR generation or link shortening into a CRM, print workflow, marketing automation tool, or any backend system.
Base URL: https://qrcodestack.com/api/v1. Auth: Authorization: Bearer qrs_<your_key>.
All responses are JSON. Timestamps are RFC 3339 UTC.
curl https://qrcodestack.com/api/v1/me \ -H "Authorization: Bearer qrs_YOUR_KEY"
| Plan | Per minute | Per month | Bulk endpoint |
|---|---|---|---|
| Starter | n/a | n/a | No |
| Pro | 60 | 5,000 | No |
| Business | 600 | 100,000 | Yes |
Exceeding either window returns HTTP 429 with a Retry-After header.
v1 covers dynamic QR codes and short links. API keys use scopes:
qr:read / qr:write for QR codes,
links:read / links:write for short links
(plus wildcards * and links:*).
| Method | Path | Scope | What it does |
|---|---|---|---|
| GET | /me | — | Account info + plan + usage |
| POST | /qr-codes | qr:write | Create a dynamic QR code |
| GET | /qr-codes | qr:read | List QR codes (paginated) |
| GET | /qr-codes/{id} | qr:read | Get one QR code |
| PATCH | /qr-codes/{id} | qr:write | Update destination / design |
| DELETE | /qr-codes/{id} | qr:write | Soft-delete a QR code |
| GET | /qr-codes/{id}/analytics | analytics:read | Aggregated scan analytics |
| GET | /qr-codes/{id}/scans | analytics:read | Individual scan event log (engaged traffic by default; ?traffic=all for bots and previews) |
| POST | /qr-codes/bulk | qr:bulk | Create up to 500 QR codes in one call (Business plan only) |
| GET | /links | links:read | List short links |
| GET | /links/{id} | links:read | Get one short link |
| POST | /links | links:write | Create a short link |
| PATCH | /links/{id} | links:write | Update a short link |
| DELETE | /links/{id} | links:write | Soft-delete a short link |
| POST | /deeplinks/claim | links:read | Claim a deferred deep-link install (mobile SDK) |
| POST | /affiliates/conversions | links:write | Record an affiliate lead/sale/click |
| GET | /link-domains | links:read | List branded short-link domains |
| POST | /link-domains | links:write | Add a branded short-link domain (returns DNS records) |
| POST | /link-domains/{id}/verify | links:write | Verify DNS + provision TLS for a link domain |
| DELETE | /link-domains/{id} | links:write | Remove a branded short-link domain |
| GET | /custom-domains | qr:read | Get QR scan white-label domain (or null) |
| POST | /custom-domains | qr:write | Claim QR scan custom domain (Business) |
| POST | /custom-domains/verify | qr:write | Verify DNS + SSL for QR scan domain |
| DELETE | /custom-domains/{id} | qr:write | Remove QR scan custom domain |
Link domains power short URLs on go.yourbrand.com (CNAME → links.qrcodestack.com).
Custom domains power white-label QR scan pages (CNAME → customers.qrcodestack.com, Business).
After POST, add the returned DNS records, then call the matching /verify endpoint.
Short-link create/update accepts the same fields as the dashboard:
destination_url (required on create),
slug, title, tags, domain_id,
utm_config, activates_at, expires_at,
max_clicks, expired_url, password (write-only;
responses expose password_protected only),
routing_config, deeplink_config, pixel_config,
webhook_url, cloaking_enabled,
og_title / og_description / og_image_url,
ab_config, campaign_id, folder_id,
allow_indexing. Plan gates match the dashboard (Pro+ for UTM/expiry/routing;
Business for deep links and A/B). Use /link-domains to register a branded host,
then pass its id as domain_id on create.
When creating an API key, enable links:read / links:write explicitly —
legacy keys default to QR + analytics only and will get SCOPE_DENIED on
/links until you regenerate with those scopes.
curl -X POST https://qrcodestack.com/api/v1/links \
-H "Authorization: Bearer qrs_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{
"destination_url": "https://shop.example.com/spring",
"slug": "spring-sale",
"title": "Spring promo",
"utm_config": {
"utm_source": "sms",
"utm_medium": "link",
"utm_campaign": "spring"
}
}'
curl -X POST https://qrcodestack.com/api/v1/qr-codes \
-H "Authorization: Bearer qrs_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "Spring promo",
"type": "url",
"destination_url": "https://shop.example.com/spring",
"render_customizations": {
"dot_color": "#0F172A",
"dot_shape": "rounded",
"logo_url": "https://shop.example.com/logo.png",
"frame": "scan-me-bottom"
}
}'
Errors are JSON: { "success": false, "error": "<message>", "code": "<machine_code>" }.
Standard HTTP status codes apply (401 unauthenticated, 403 forbidden by plan, 404 not found,
422 validation failure, 429 rate-limited, 5xx server error).
Current version is v1. Breaking changes ship under v2; non-breaking
additions (new optional fields, new endpoints) land under v1 without notice.
Email support@qrcodestack.com or open a ticket from your dashboard.
Loading interactive API explorer…