Skip to main content

Changelog

This document provides a versioned summary of all public API updates for QRForge.
Only production‑ready, developer‑facing changes are listed here.


2025‑11‑14 — API v1 (Initial Public Release)​

New Endpoints​

  • POST /v1/qr-codes
    Create a new QR code programmatically.

    • GET /v1/qr-codes/{id}
      Retrieve a QR code by its document ID.
  • GET /v1/qr-codes/by-slug
    Retrieve a QR code using its public slug.

  • GET /v1/qr-codes
    List QR codes with pagination and filtering.

    • PATCH /v1/qr-codes/{id}
      Update QR label or redirect URL (with secure field‑level controls).
  • POST /v1/projects
    Create a new project.

  • GET /v1/projects
    List all accessible projects with pagination.

Core Features​

  • Secure API Key authentication using x-api-key.
  • Per‑user quota metering (minute/day API rate limits).
  • Strong ownership checks (QR and project scoping).
  • Integration with QRForge Rendering Pipeline (Cloud Run).
  • Slug‑based QR retrieval.
  • Immutable audit trail for created_via and timestamps.

2025‑11‑20 — Developer Portal Enhancements​

  • Fully documented API reference for v1.
  • Added topics:
    • Authentication
    • Projects
    • QR Codes
    • Pagination
    • Rate Limits
    • Errors
    • API Keys
    • Analytics (v1 reality + v2 roadmap)

2026‑08‑08 — Conditional Redirection Parity​

New Features​

  • Conditional redirect rules — the public API now has full parity with the app for conditional redirection: device‑based rules, country‑based rules, expiry dates, and scan‑limit rules can all be configured via PATCH /v1/qr-codes/{id}.

2026‑08‑12 — Rate Limit & Pagination Fixes​

Fixes​

  • Public API rate limits are now actually enforced. A gap in the rate‑limit check meant every subscription tier had an effectively unlimited request rate on public API endpoints. This is now closed.
  • apiCreateQr day‑window reset model unified. The daily quota window for POST /v1/qr-codes used a different reset model than the other endpoints; it now resets consistently with the rest of the API.
  • NaN rate‑limit values no longer silently disable enforcement. A configuration edge case could produce a NaN rate‑limit value, which silently disabled rate limiting entirely on all 7 public API endpoints. Malformed limits are now rejected instead of bypassed.
  • GET /v1/projects pagination fixed. Pagination on the projects list endpoint was completely broken and could return incorrect or duplicate pages; cursor‑based pagination now works as documented.
  • API key management endpoints are now rate‑limited. apiKeys.js previously had no rate limiting of its own, including a NaN‑based bypass on the maximum‑keys‑per‑account cap. Both are now enforced.

2026‑08‑14 — QR Update & Project Archive Fixes​

Fixes​

  • PATCH /v1/qr-codes/{id} no longer silently ignores invalid redirect_url updates. Attempting to set redirect_url on a non‑URL‑type QR code previously no‑op'd without feedback; it now returns a clear error.
  • Archived projects now actually stop serving their QR codes. Archiving a project previously left its QR codes reachable and scannable; archived‑project QR codes now correctly stop being served.

Upcoming in v2​

(In active development — no fixed ETA)

Planned Additions​

  • Analytics Export API
    Generate downloadable CSV/JSON exports powered by BigQuery.

  • Webhook System
    Events: qr.scan, qr.updated, project.updated, more.

  • OAuth2 Client Credentials (Enterprise tier)
    Machine‑to‑machine secure authentication.

  • QR Templates API
    Create/update style presets for batch QR creation.

  • Bulk Operations API
    Batch create and batch update QR codes.