API Keys
QRForge uses server-to-server API keys to authenticate and authorize all public API traffic.
API keys are managed per user account and scoped to your subscription plan and associated rate limits.
Creating an API Key
API keys are created in the QRForge dashboard:
Dashboard → Subscription (Manage Plan) → API Keys → “Create API Key”
Each key is generated in the format:
api_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
QRForge does not issue test keys.
All keys are live keys, subject to your plan’s API quotas.
Authentication Header
All API requests must include the following header:
x-api-key: YOUR_API_KEY
Example:
curl -X GET \
-H "x-api-key: api_live_123456789" \
"https://api.qrforge.link/v1/qr-codes"
Missing or incorrect API keys return:
401 unauthorized
API Key Permissions
Each API key is tied to:
- Your user account
- Your active subscription plan
- Your per‑minute and per‑day rate limits
Every key is issued with a single fixed scope (qr.write) — there is currently no read‑only, write, or analytics permission choice, and no per‑key environment (production/staging/dev) assignment. Authorization is enforced at the account/plan level (whether API access is enabled for your subscription), not by per‑key scope.
With a valid key, you can:
- Create QR codes
- Update QR codes
- Retrieve QR codes
- List QR codes
- Manage projects (create, list)
You cannot, via the API:
- Modify billing
- Delete QR codes (QRs are archived, not deleted)
- Modify subscription state
- Access internal system data
Rotating API Keys
There is no one‑click "rotate" action. To rotate a key, create a new key, switch your services over to it, and then revoke the old one. See Key Rotation (Best Practice) in the Authentication guide for the full workflow.
Revoking API Keys
You may revoke any API key at any time.
Once revoked, the key cannot be recovered.
Use revocation if:
- You suspect your key is compromised
- You no longer need automation on that key
- You want to reduce exposure risk
Best Practices
-
Do not expose API keys in frontend code.
They are backend‑only. -
Store your key in environment variables, not hardcoded source files.
-
Rotate keys regularly (every 60–90 days recommended).
-
Use separate keys for separate environments or workloads.
-
Never commit keys into Git repositories.
Example Error Responses
| Status | Code | Meaning |
|---|---|---|
| 401 | unauthorized | API key missing, invalid, or revoked |
| 403 | api_access_disabled | API access is not enabled for your account |
| 429 | rate_limited | General per-key rate limit exceeded |
| 429 | rate_limit_minute / rate_limit_day | Per-minute or per-day request quota exceeded — evaluated on every authenticated request, not just QR creation |
See the Error Reference for the full list of codes.
If you need higher throughput or multiple API keys, contact support for an Enterprise plan.