← Back to blog
AI & Automation4 min read

QR Code API: Automatically create, modify, and evaluate QR codes

Bild von Unsplash

Purpose of a QR Code API

A QR Code API is a programming interface: Instead of clicking in the browser, your program sends requests to the QR Code service and receives responses. This allows codes to be generated directly from a shop, an inventory management system, a script, or a spreadsheet.

This is worthwhile as soon as work repeats: hundreds of codes for tables or products, monthly scan reports, changing many targets after a relaunch. And it only works with dynamic codes. A dynamic QR Code from Same-QR contains a short, constant address; the target behind it is hosted by us and can be changed at any time without reprinting.

What the Same-QR API covers

The REST API is located at https://sameqr.com/api/v1. It calls the same functions as the dashboard, with the same plan limits and checks:

  • List, read, create, modify, and delete QR codes.
  • The statistics of a code: scans, creation date, number of target changes.
  • Create, modify, publish, and take offline hosted pages such as menus, price lists, opening hours, link pages, promotions, wineries, wine e-labels, and contact pages.
  • Read a menu from up to four photos or a PDF.
  • Manage labels and customer projects, and read enquiries from contact forms.

A machine-readable description of all enquiries is available at /api/v1/openapi.json; the documentation is at sameqr.com/entwickler.

API Key and Permissions

You create the key in the dashboard under Account, section "Access for CLI, scripts and agents". You select one of three levels, "read only", "read + write" (create, change names and texts), or "full" (additionally change targets, take offline, delete), and a duration of 30, 90, 180, or 365 days, or unlimited if necessary. The key starts with sqr_live_ and is displayed exactly once. We only store a checksum.

A key that is allowed only read access receives a clear rejection for every modifying request. This is the right choice for reports and evaluations. Everything that changes, where a printed code leads, is additionally protected: target changes, taking offline, and deletion require the "full" level and confirmation with the previously read state, and via the API, at most 10 per hour and 30 per day are affected. There is no such limit in the dashboard. Every key can be revoked at any time and becomes invalid immediately.

A typical workflow

The key belongs in the Authorization header, never in a URL. You store the key as an environment variable beforehand. This is how you list your codes and change the target of a code:

curl -H "Authorization: Bearer $SAMEQR_API_KEY" https://sameqr.com/api/v1/qr

curl -X PATCH https://sameqr.com/api/v1/qr/<id> \
  -H "Authorization: Bearer $SAMEQR_API_KEY" -H "Content-Type: application/json" \
  -H "X-Confirm: <stand>" \
  -d '{"targetUrl":"https://example.com/karte-neu"}'

The value for X-Confirm, the state, is provided by the read request on /api/v1/qr/<id>. Only what you send is changed. If you want to ensure that no one has changed the same code in the meantime, you send the read state as _rev. If something has changed, nothing is overwritten, and the response contains the current state. Errors always return in the same format, with status, code, and a clear message.

Limits and best practices

Each key allows a maximum of 120 requests per minute. Additionally, there is an hourly limit depending on the plan: 60 in the Free plan, 300 in Start, 1,000 in Pro, and 5,000 in Agentur. The limits catch errors, such as a script in an infinite loop, and do not interfere with honest usage.

  • Test first with a read-only key, then write.
  • Test new workflows on a single code and scan with your phone.
  • Avoid deletion where a new target suffices. Deleted codes and their short links cannot be recovered.
  • Create a separate key for each program and keep it in a password manager or an environment variable.

Conclusion: why Same-QR

Same-QR provides you with the API not as an expensive extra, but in every plan, with the same features as in the dashboard: codes, statistics, menus, hosted pages, labels, and projects. Additionally, there are clear permissions per key, honest error messages, and a nightly check of all targets, which notifies you via email if one is unreachable.

Get started right away: sign up for free at sameqr.com, two dynamic QR codes are free forever. API, CLI and MCP server are included in every plan, and the documentation is at sameqr.com/entwickler.

Create dynamic QR codes for free
Start with 2 dynamic QR codes that are free forever. No subscription, no credit card.
Start free now →

Frequently asked questions

Is the API included in the Free plan?

Yes. You can create keys in every plan. The plan determines how many codes you have and how many enquiries per hour are possible.

Can I change the target of a printed code via the API?

Yes, for every dynamic code from Same-QR. In the free plan, the number of target changes per code is limited; in the paid plans, it is not.

What happens if a key falls into the wrong hands?

You revoke it in the dashboard, then it becomes invalid immediately. Changing a password also revokes all keys of the account.

Where can I find all enquiries?

In the description at /api/v1/openapi.json and in the guide at sameqr.com/entwickler.

Reserve a spot

Reserve your spot before we go live.

One email as soon as the tool goes live — including pricing and the free plan. No spam, unsubscribe any time.

Only until launchLaunching in the next few weeks
  • Your free account is reserved — there is nothing to pay yet anyway
  • 90 days of unlimited destination changes instead of 30, only for early sign-ups
  • Launch price locked in, even if we raise prices later

By subscribing you consent to receiving the newsletter. You can withdraw consent at any time via the unsubscribe link in every email.

Keep reading