Skip to main content

API Keys

QRForge uses server-to-server API keys to authenticate and authorize all public API traffic.
API keys are managed per user account and scoped to your subscription plan and associated rate limits.


Creating an API Key​

API keys are created in the QRForge dashboard:

Dashboard → Subscription (Manage Plan) → API Keys → “Create API Key”

Each key is generated in the format:

api_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

QRForge does not issue test keys.
All keys are live keys, subject to your plan’s API quotas.


Authentication Header​

All API requests must include the following header:

x-api-key: YOUR_API_KEY

Example:

curl -X GET \
-H "x-api-key: api_live_123456789" \
"https://api.qrforge.link/v1/qr-codes"

Missing or incorrect API keys return:

401 unauthorized

API Key Permissions​

Each API key is tied to:

  • Your user account
  • Your active subscription plan
  • Your per‑minute and per‑day rate limits

Every key is issued with a single fixed scope (qr.write) — there is currently no read‑only, write, or analytics permission choice, and no per‑key environment (production/staging/dev) assignment. Authorization is enforced at the account/plan level (whether API access is enabled for your subscription), not by per‑key scope.

With a valid key, you can:

  • Create QR codes
  • Update QR codes
  • Retrieve QR codes
  • List QR codes
  • Manage projects (create, list)

You cannot, via the API:

  • Modify billing
  • Delete QR codes (QRs are archived, not deleted)
  • Modify subscription state
  • Access internal system data

Rotating API Keys​

There is no one‑click "rotate" action. To rotate a key, create a new key, switch your services over to it, and then revoke the old one. See Key Rotation (Best Practice) in the Authentication guide for the full workflow.


Revoking API Keys​

You may revoke any API key at any time.
Once revoked, the key cannot be recovered.

Use revocation if:

  • You suspect your key is compromised
  • You no longer need automation on that key
  • You want to reduce exposure risk

Best Practices​

  • Do not expose API keys in frontend code.
    They are backend‑only.

  • Store your key in environment variables, not hardcoded source files.

  • Rotate keys regularly (every 60–90 days recommended).

  • Use separate keys for separate environments or workloads.

  • Never commit keys into Git repositories.


Example Error Responses​

StatusCodeMeaning
401unauthorizedAPI key missing, invalid, or revoked
403api_access_disabledAPI access is not enabled for your account
429rate_limitedGeneral per-key rate limit exceeded
429rate_limit_minute / rate_limit_dayPer-minute or per-day request quota exceeded — evaluated on every authenticated request, not just QR creation

See the Error Reference for the full list of codes.


If you need higher throughput or multiple API keys, contact support for an Enterprise plan.