QR Code API: Automatically create, modify, and evaluate QR codes
Purpose of a QR Code API
A QR Code API is a programming interface: Instead of clicking in the browser, your program sends requests to the QR Code service and receives responses. This allows codes to be generated directly from a shop, an inventory management system, a script, or a spreadsheet.
This is worthwhile as soon as work repeats: hundreds of codes for tables or products, monthly scan reports, changing many targets after a relaunch. And it only works with dynamic codes. A dynamic QR Code from Same-QR contains a short, constant address; the target behind it is hosted by us and can be changed at any time without reprinting.
What the Same-QR API covers
The REST API is located at https://sameqr.com/api/v1. It calls the same functions as the dashboard, with the same plan limits and checks:
- List, read, create, modify, and delete QR codes.
- The statistics of a code: scans, creation date, number of target changes.
- Create, modify, publish, and take offline hosted pages such as menus, price lists, opening hours, link pages, promotions, wineries, wine e-labels, and contact pages.
- Read a menu from up to four photos or a PDF.
- Manage labels and customer projects, and read enquiries from contact forms.
A machine-readable description of all enquiries is available at /api/v1/openapi.json; the documentation is at sameqr.com/entwickler.
API Key and Permissions
You create the key in the dashboard under Account, section "Access for CLI, scripts and agents". You select one of three levels, "read only", "read + write" (create, change names and texts), or "full" (additionally change targets, take offline, delete), and a duration of 30, 90, 180, or 365 days, or unlimited if necessary. The key starts with sqr_live_ and is displayed exactly once. We only store a checksum.
A key that is allowed only read access receives a clear rejection for every modifying request. This is the right choice for reports and evaluations. Everything that changes, where a printed code leads, is additionally protected: target changes, taking offline, and deletion require the "full" level and confirmation with the previously read state, and via the API, at most 10 per hour and 30 per day are affected. There is no such limit in the dashboard. Every key can be revoked at any time and becomes invalid immediately.
A typical workflow
The key belongs in the Authorization header, never in a URL. You store the key as an environment variable beforehand. This is how you list your codes and change the target of a code:
curl -H "Authorization: Bearer $SAMEQR_API_KEY" https://sameqr.com/api/v1/qr
curl -X PATCH https://sameqr.com/api/v1/qr/<id> \
-H "Authorization: Bearer $SAMEQR_API_KEY" -H "Content-Type: application/json" \
-H "X-Confirm: <stand>" \
-d '{"targetUrl":"https://example.com/karte-neu"}'The value for X-Confirm, the state, is provided by the read request on /api/v1/qr/<id>. Only what you send is changed. If you want to ensure that no one has changed the same code in the meantime, you send the read state as _rev. If something has changed, nothing is overwritten, and the response contains the current state. Errors always return in the same format, with status, code, and a clear message.
Limits and best practices
Each key allows a maximum of 120 requests per minute. Additionally, there is an hourly limit depending on the plan: 60 in the Free plan, 300 in Start, 1,000 in Pro, and 5,000 in Agentur. The limits catch errors, such as a script in an infinite loop, and do not interfere with honest usage.
- Test first with a read-only key, then write.
- Test new workflows on a single code and scan with your phone.
- Avoid deletion where a new target suffices. Deleted codes and their short links cannot be recovered.
- Create a separate key for each program and keep it in a password manager or an environment variable.
Conclusion: why Same-QR
Same-QR provides you with the API not as an expensive extra, but in every plan, with the same features as in the dashboard: codes, statistics, menus, hosted pages, labels, and projects. Additionally, there are clear permissions per key, honest error messages, and a nightly check of all targets, which notifies you via email if one is unreachable.
Get started right away: sign up for free at sameqr.com, two dynamic QR codes are free forever. API, CLI and MCP server are included in every plan, and the documentation is at sameqr.com/entwickler.
Frequently asked questions
Yes. You can create keys in every plan. The plan determines how many codes you have and how many enquiries per hour are possible.
Yes, for every dynamic code from Same-QR. In the free plan, the number of target changes per code is limited; in the paid plans, it is not.
You revoke it in the dashboard, then it becomes invalid immediately. Changing a password also revokes all keys of the account.
In the description at /api/v1/openapi.json and in the guide at sameqr.com/entwickler.
Reserve your spot before we go live.
One email as soon as the tool goes live — including pricing and the free plan. No spam, unsubscribe any time.
- Your free account is reserved — there is nothing to pay yet anyway
- 90 days of unlimited destination changes instead of 30, only for early sign-ups
- Launch price locked in, even if we raise prices later
By subscribing you consent to receiving the newsletter. You can withdraw consent at any time via the unsubscribe link in every email.