API reference
Card templates endpoints
Read the templates a card can be created from, and the field rules each one imposes.
List templates
Returns the card templates in the account.
API key required. Scope: templates:read. Campaign-scoped keys are refused. Plan: Pro, or the Business card plan.
Request
| Header | Required | Value |
|---|---|---|
Authorization | Required | Bearer YOUR_API_KEY. X-API-Key: YOUR_API_KEY is accepted instead. |
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
limit | integer | Optional | Items per page, 1 to 100. Default: 25. |
offset | integer | Optional | How many items to skip. Default: 0. |
Example request
curl "https://api.qrbold.com/api/public/v1/templates" \
-H "Authorization: Bearer $QRBOLD_API_KEY"Response
200 A list envelope of card_template objects.
{
"object": "list",
"data": [
{
"object": "card_template",
"id": "cmf3k1p7d0002",
"name": "Company standard",
"policy": {
"theme": "locked",
"blocks": "reorder_only",
"fields": {
"company": {
"mode": "locked",
"value": "Analytical Engines Ltd"
},
"firstName": {
"mode": "required"
}
}
},
"createdAt": "2026-09-01T08:00:00.000Z",
"updatedAt": "2026-09-20T14:12:00.000Z"
}
],
"pagination": {
"total": 1,
"limit": 25,
"offset": 0,
"hasMore": false
}
}Errors
| Status | Code | When | Retry? |
|---|---|---|---|
422 | validation_failed | The request body or the query string did not pass validation. | Only after changing the request or the account |
Every endpoint can also answer 401 invalid_api_key, 403 forbidden, 403 upgrade_required_api, 404 unknown_endpoint, 429 rate limited and 500 internal_error. One failing response is shown below.
{
"error": {
"type": "invalid_request",
"code": "validation_failed",
"message": "One or more fields are invalid.",
"details": [
{
"field": "fields.links.0.type",
"message": "Invalid enum value",
"code": "invalid_enum_value"
},
{
"field": "shortCode",
"message": "Slugs can only contain letters, numbers, and hyphens",
"code": "invalid_string"
}
]
}
}Related
Retrieve a template
Returns one template, including the field policy it applies to its cards.
API key required. Scope: templates:read. Campaign-scoped keys are refused. Plan: Pro, or the Business card plan.
Request
| Header | Required | Value |
|---|---|---|
Authorization | Required | Bearer YOUR_API_KEY. X-API-Key: YOUR_API_KEY is accepted instead. |
| Name | Type | Required | Description |
|---|---|---|---|
id | string | Required | The template’s id. |
Example request
curl "https://api.qrbold.com/api/public/v1/templates/cmf3k1p7d0002" \
-H "Authorization: Bearer $QRBOLD_API_KEY"Response
200 The card_template object.
{
"object": "card_template",
"id": "cmf3k1p7d0002",
"name": "Company standard",
"policy": {
"theme": "locked",
"blocks": "reorder_only",
"fields": {
"company": {
"mode": "locked",
"value": "Analytical Engines Ltd"
},
"firstName": {
"mode": "required"
}
}
},
"createdAt": "2026-09-01T08:00:00.000Z",
"updatedAt": "2026-09-20T14:12:00.000Z"
}Errors
| Status | Code | When | Retry? |
|---|---|---|---|
404 | resource_not_found | Nothing with that id exists in this account. | No |
Every endpoint can also answer 401 invalid_api_key, 403 forbidden, 403 upgrade_required_api, 404 unknown_endpoint, 429 rate limited and 500 internal_error. One failing response is shown below.
{
"error": {
"type": "not_found",
"code": "resource_not_found",
"message": "Card not found"
}
}Good to know
- policy.fields lists a mode per field: locked, prefilled, required, optional or hidden. Writing to a locked or hidden field, or leaving a required one empty, answers 422.