Changelog
This document provides a versioned summary of all public API updates for QRForge.
Only production‑ready, developer‑facing changes are listed here.
2025‑11‑14 — API v1 (Initial Public Release)
New Endpoints
-
POST /v1/qr-codes
Create a new QR code programmatically.- GET /v1/qr-codes/{id}
Retrieve a QR code by its document ID.
- GET /v1/qr-codes/{id}
-
GET /v1/qr-codes/by-slug
Retrieve a QR code using its public slug. -
GET /v1/qr-codes
List QR codes with pagination and filtering.- PATCH /v1/qr-codes/{id}
Update QR label or redirect URL (with secure field‑level controls).
- PATCH /v1/qr-codes/{id}
-
POST /v1/projects
Create a new project. -
GET /v1/projects
List all accessible projects with pagination.
Core Features
- Secure API Key authentication using
x-api-key. - Per‑user quota metering (minute/day API rate limits).
- Strong ownership checks (QR and project scoping).
- Integration with QRForge Rendering Pipeline (Cloud Run).
- Slug‑based QR retrieval.
- Immutable audit trail for
created_viaand timestamps.
2025‑11‑20 — Developer Portal Enhancements
- Fully documented API reference for v1.
- Added topics:
- Authentication
- Projects
- QR Codes
- Pagination
- Rate Limits
- Errors
- API Keys
- Analytics (v1 reality + v2 roadmap)
2026‑08‑08 — Conditional Redirection Parity
New Features
- Conditional redirect rules — the public API now has full parity with the app for conditional redirection: device‑based rules, country‑based rules, expiry dates, and scan‑limit rules can all be configured via
PATCH /v1/qr-codes/{id}.
2026‑08‑12 — Rate Limit & Pagination Fixes
Fixes
- Public API rate limits are now actually enforced. A gap in the rate‑limit check meant every subscription tier had an effectively unlimited request rate on public API endpoints. This is now closed.
apiCreateQrday‑window reset model unified. The daily quota window forPOST /v1/qr-codesused a different reset model than the other endpoints; it now resets consistently with the rest of the API.- NaN rate‑limit values no longer silently disable enforcement. A configuration edge case could produce a
NaNrate‑limit value, which silently disabled rate limiting entirely on all 7 public API endpoints. Malformed limits are now rejected instead of bypassed. GET /v1/projectspagination fixed. Pagination on the projects list endpoint was completely broken and could return incorrect or duplicate pages; cursor‑based pagination now works as documented.- API key management endpoints are now rate‑limited.
apiKeys.jspreviously had no rate limiting of its own, including aNaN‑based bypass on the maximum‑keys‑per‑account cap. Both are now enforced.
2026‑08‑14 — QR Update & Project Archive Fixes
Fixes
PATCH /v1/qr-codes/{id}no longer silently ignores invalidredirect_urlupdates. Attempting to setredirect_urlon a non‑URL‑type QR code previously no‑op'd without feedback; it now returns a clear error.- Archived projects now actually stop serving their QR codes. Archiving a project previously left its QR codes reachable and scannable; archived‑project QR codes now correctly stop being served.
Upcoming in v2
(In active development — no fixed ETA)
Planned Additions
-
Analytics Export API
Generate downloadable CSV/JSON exports powered by BigQuery. -
Webhook System
Events:qr.scan,qr.updated,project.updated, more. -
OAuth2 Client Credentials (Enterprise tier)
Machine‑to‑machine secure authentication. -
QR Templates API
Create/update style presets for batch QR creation. -
Bulk Operations API
Batch create and batch update QR codes.