Developers

Same-QR for terminal, agents and chat

Everything you do in the dashboard also works from the command line, with your coding agent or right in a chat with ChatGPT or Claude. The same plan limits and checks apply as in the dashboard.

1. Create a key

In the dashboard under Account → “Access for CLI, scripts and agents”. Three levels: “read only”, “read + write” (create, edit drafts) and “full” (also change targets, change and publish published pages, take offline, delete — each with confirmation). The key is shown exactly once; we only store its checksum. Never put it in a URL or pass it as a command-line argument. Open the dashboard →

2. Command line

Node.js 18 or newer. sameqr login asks for the key with hidden input and stores it readable only by you (~/.config/sameqr/config.json). In scripts, set SAMEQR_API_KEY instead. Add --json for machine-readable output.

npm install -g sameqr
sameqr login
sameqr qr list
sameqr qr create --name "Speisekarte" --url https://example.com/karte
sameqr qr update <id> --url https://example.com/karte-neu
sameqr seite publish menu/zum-loewen
sameqr karte import karte.pdf --seite menu/zum-loewen
sameqr qr list --json

3. MCP for coding agents

The MCP server gives your agent the same tools as the API. The key comes from the environment variable SAMEQR_API_KEY, never directly in the config file.

Claude Code

claude mcp add --transport http sameqr https://sameqr.com/api/mcp \
  --header "Authorization: Bearer $SAMEQR_API_KEY"

Cursor · ~/.cursor/mcp.json

{
  "mcpServers": {
    "sameqr": {
      "url": "https://sameqr.com/api/mcp",
      "headers": { "Authorization": "Bearer ${env:SAMEQR_API_KEY}" }
    }
  }
}

Codex · ~/.codex/config.toml

[mcp_servers.sameqr]
url = "https://sameqr.com/api/mcp"
bearer_token_env_var = "SAMEQR_API_KEY"

4. ChatGPT and Claude.ai

No key needed there: add the address as a connector, sign in to Same-QR in the browser and allow access. By default the app may only read; you allow creating and drafts with one checkbox; changing targets, changing published pages, taking offline and deleting with a second — the app asks you first every time and shows all changes. You can disconnect at any time in the dashboard.

  • ChatGPT: Settings → Apps & Connectors → Create (developer mode)
  • Enter the MCP address below as URL, authentication OAuth
  • Sign in, check the rights, “Allow”
  • Claude.ai: Settings → Connectors → Add custom connector
  • Enter the MCP address below as URL
  • Connect, sign in to Same-QR, “Allow”
https://sameqr.com/api/mcp

5. REST API

Base address /api/v1, authentication via Authorization: Bearer. Changing targets, changing or publishing published pages, taking offline and deleting need the previously read state in the X-Confirm header. Errors always come as { error: { status, code, message } }. The full description is available as OpenAPI. OpenAPI description →

curl -H "Authorization: Bearer $SAMEQR_API_KEY" https://sameqr.com/api/v1/qr

# Ziel aendern: erst den Stand lesen, dann mit X-Confirm bestaetigen
STAND=$(curl -s -H "Authorization: Bearer $SAMEQR_API_KEY" https://sameqr.com/api/v1/qr/<id> | jq -r .stand)
curl -X PATCH https://sameqr.com/api/v1/qr/<id> \
  -H "Authorization: Bearer $SAMEQR_API_KEY" \
  -H "X-Confirm: $STAND" \
  -H "Content-Type: application/json" \
  -d '{"targetUrl":"https://example.com/karte-neu"}'

Tools

The same names in MCP, REST and CLI. Tools marked ✎ change something and need “read + write”.

konto_infoGET /api/v1/kontoKonto und Tarif
qr_auflistenGET /api/v1/qrQR-Codes auflisten
qr_lesenGET /api/v1/qr/{id}QR-Code lesen
qr_statistikGET /api/v1/qr/{id}/statsScans eines QR-Codes
qr_anlegen ✎POST /api/v1/qrQR-Code anlegen
qr_aendern ✎PATCH /api/v1/qr/{id}QR-Code ändern
qr_loeschen ✎DELETE /api/v1/qr/{id}QR-Code löschen
seiten_auflistenGET /api/v1/seitenSeiten auflisten
seite_anlegen ✎POST /api/v1/seitenSeite anlegen
seite_lesenGET /api/v1/seiten/{pfad}/{slug}Seite lesen
seite_aendern ✎PATCH /api/v1/seiten/{pfad}/{slug}Seite ändern
seite_veroeffentlichen ✎POST /api/v1/seiten/{pfad}/{slug}/veroeffentlichenSeite veröffentlichen
seite_offline ✎POST /api/v1/seiten/{pfad}/{slug}/offlineSeite offline nehmen
seite_loeschen ✎DELETE /api/v1/seiten/{pfad}/{slug}Seite löschen
seite_anfragenGET /api/v1/seiten/{pfad}/{slug}/anfragenAnfragen einer Seite
designs_auflistenGET /api/v1/designsDesigns auflisten
karte_einlesen ✎POST /api/v1/karte/importKarte aus Foto/PDF einlesen
labels_auflistenGET /api/v1/labelsLabels auflisten
label_anlegen ✎POST /api/v1/labelsLabel anlegen
label_aendern ✎PATCH /api/v1/labels/{id}Label ändern
label_loeschen ✎DELETE /api/v1/labels/{id}Label löschen
projekte_auflistenGET /api/v1/projekteProjekte auflisten
projekt_anlegen ✎POST /api/v1/projekteProjekt anlegen
projekt_aendern ✎PATCH /api/v1/projekte/{id}Projekt ändern
projekt_loeschen ✎DELETE /api/v1/projekte/{id}Projekt löschen

Security

  • We store keys and tokens only as SHA-256 checksums.
  • At most 10 keys per account, revocable at any time; changing your password revokes all keys and disconnects all apps.
  • Managing keys, password and subscription only works in the browser, never via the API.
  • Changing targets, taking offline and deleting with a key or app only works via /api/v1 or MCP: with confirmation, at most 10 per hour and 30 per day per key/app (60 per day per account). You get an email right away, and every target can be restored on the code with one click.
  • At most 120 tool calls per minute and key (in MCP every call counts), plus the hourly limit of your plan.
  • Agents get every result marked as data; texts from guests are never instructions.
  • The CLI asks before changing targets and deleting (without a terminal only with --yes) and only sends a stored key to the address you signed in with.
  • Menu import: up to 9 MB per request (one PDF up to 6 MB or up to four photos).

Questions or a bug? Write to us via “Report a problem”.