Skip to content
API key

Resources

Frequently asked questions

Short answers to the questions developers ask first. Each one links to the page with the detail.

I have an API key. Where do I start?

Send GET /me to confirm the key works, then create a card with POST /cards, then download its QR code with GET /qr-codes/{card id}/image. The quickstart and the end-to-end tutorial walk through exactly that. Quickstart.

Which plan do I need?

The REST API is included in the Pro plan and in the Business card plan. Either one is enough. On other plans a key can be created but only works with AI assistants; REST requests answer 403 upgrade_required_api. Plans and access.

How do I authenticate?

Send the key in a header on every request: Authorization: Bearer YOUR_API_KEY. X-API-Key: YOUR_API_KEY is accepted as an alternative. There is no OAuth flow and no token exchange. Authentication.

I lost my API key. Can I see it again?

No. QRBold stores only a hash, so the key is shown once, when it is created. Create a new key and revoke the old one. Rotate and revoke.

Is there a sandbox or test mode?

No. There is one environment, and every request acts on your real account. Test with clearly named records and delete them afterwards. Campaign endpoints have a dry-run call that creates nothing. Dry-run a payload.

How do I get the QR code for a digital business card?

Call GET /qr-codes/{id}/image with the card’s id. Every card already has a QR code, so you do not create one. The response is the image file. Get the QR code for a card.

What is the public link for a card?

It is the url field of the card object, for example https://qrbold.com/c/ada-lovelace. Use it exactly as returned; do not build it yourself, because accounts with a custom domain get a different domain.

Can I use the QR image endpoint directly in an <img> tag?

No. It needs your API key, and a key must never be in a web page. Download the image on your server and serve it from your own storage.

Can I call the API from my website’s JavaScript or my mobile app?

No. Anything shipped to a user’s device can be read by that user, so the key would be public. Call the API from your server and have your front end call your server. Browser or server.

Why did updating one field clear the others?

PATCH /cards/{id} replaces the card’s data rather than merging it. Read the card, change the fields object, and send the whole object back. Update a card.

Can I set the QR code’s colours or add a logo through the API?

No. Design the code in the dashboard and the image endpoint returns that design. The API controls only the file format, the size and a transparent background. Styling.

Can I change where a printed QR code goes?

Yes, for URL codes: PATCH /qr-codes/{id} with a new destinationUrl. The printed code stays the same. A card’s QR code always opens that card, and updates to the card show immediately. Change, pause and delete a code.

Can I create a PDF, image or video QR code through the API?

Not directly. The API creates URL codes only and has no file upload. Host the file yourself and create a URL code that points at it, or create the file code in the dashboard. PDF, image and video.

Is there a bulk or batch endpoint?

No. One request creates one card or one code. Loop inside the rate limit, or use a campaign endpoint, which accepts your own JSON and refuses duplicates. Bulk creation.

How do I avoid creating the same card twice?

Send an Idempotency-Key header so a retried request returns the original card. For protection that lasts longer than 24 hours, keep your own record of who has a card, or use a campaign endpoint, which allows one card per identifier. Duplicates and identifiers.

Are there webhooks?

No. QRBold does not notify your server of scans or changes. Poll the analytics and list endpoints on a schedule. Webhooks.

Is there an SDK?

No official SDK exists. The API is plain HTTPS and JSON. An OpenAPI document and a Postman collection are available to download. OpenAPI and Postman.

What is the rate limit?

120 requests per minute for each API key on the plans that include the REST API. Going over it answers 429; wait the number of seconds in the RateLimit-Reset header. Rate limits.

What happens to a printed QR code if I delete its card?

It stops opening the card. Deleting moves the card to Trash, from which it can be restored in the dashboard for 30 days, which brings the link back. The API cannot restore it.

Can I create separate QRBold accounts for my customers?

No. A key acts on the one account it belongs to, and everything it creates lives there. The API has no account or user management.

Not answered here? Try the troubleshooting table, or email hello@qrbold.com. Do not include your API key.