Resources
What the API does not do
The dashboard does more than the REST API. This page lists what is missing, so you can find out in a minute rather than after an afternoon of looking for an endpoint.
Not available
| Not available | What that means | What to do instead |
|---|---|---|
| Webhooks | QRBold does not send events to your server when a card is scanned, created or changed. | Poll the analytics or list endpoints on a schedule. |
| Official SDKs | There is no QRBold client library for any language. | Call the API over HTTPS; every example here uses only fetch or requests. |
| A sandbox or test environment | There is one environment. Every key starts with qrb_live_ and every request acts on the real account. | Test with clearly named records, then delete them. |
| Batch endpoints | No request creates more than one card or code. | Send one request per record inside the rate limit, or use a campaign endpoint. |
| File uploads | The API does not accept image, PDF or video bytes. | Send a link for photoUrl and similar fields; create file QR codes in the dashboard. |
| Creating PDF, image, video, page or GS1 QR codes | Only URL codes can be created. The other types are listed read-only. | Create them in the dashboard, or point a URL code at a file you host. |
| QR styling | Colours, dot shapes, logos and frames cannot be set through REST. | Design the code in the dashboard; the image endpoint returns that design. |
| Card design | A card’s layout, blocks and theme cannot be edited through REST. | Design a template in the dashboard and create cards from it with templateId. |
| Changing a card’s status or slug | PATCH /cards/:id accepts only fields and templateId. | Set status and shortCode when you create the card, or change them in the dashboard. |
| Creating or editing templates | Templates are read-only in the API. | Build them in the dashboard under Digital business cards → Templates. |
| Restoring from Trash | A deleted card or code cannot be restored through REST. | Restore it from Trash in the dashboard. |
| Static QR codes | Every code the API creates is dynamic: it encodes a QRBold short link. | Encode a URL directly with any QR library if you need a code with no redirect. |
| Raw scan events | There is no list of individual scans, and no IP addresses or visitor identifiers. | Use the aggregated analytics endpoints. |
| Leads and form submissions | Contacts captured by a card are not exposed. | Export them from the dashboard. |
| Managing API keys | Keys are created and revoked in the dashboard only. | Use Settings → Developer API. |
Webhooks
QRBold does not have webhooks. It does not call your server when a card is scanned, created, updated or deleted, and there is nothing to configure or sign.
The replacement is polling, which means asking on a schedule:
| To learn about | Poll | A sensible interval |
|---|---|---|
| New scans | GET /analytics/:id or GET /analytics/overview | Hourly |
| Cards edited in the dashboard | GET /cards, comparing updatedAt with what you stored | Daily, or before you use the data |
| New or changed QR codes | GET /qr-codes, comparing updatedAt | Daily |
There is no “changed since” filter, so a sync reads the list and compares. Keep polling well inside the rate limit.
SDKs and libraries
There are no official QRBold SDKs, in any language, and no official command-line tool. The API is plain HTTPS and JSON, and every example in these docs uses only what a language already has: fetch in JavaScript, requests in Python, and cURL.
What does exist:
- An OpenAPI document, from which you can generate a client. A generated client is your code to maintain, not a supported QRBold product.
- A Postman collection.
- A small request helper you can copy, in going to production.
AI assistants do more
QRBold also has a connector for AI assistants, described at /mcp. It uses the same API keys, is included on every plan, and can do some things the REST API cannot, such as sharing a card with somebody or emailing one. That is what the cards:share and cards:send scopes are for.
It is a different interface for a different job: an assistant acting for a person in a conversation. It is not a way to call extra REST endpoints from your code, and those two scopes unlock nothing in the REST API.