API overview
The engine is published as a small HTTP API. There are two ways to authenticate.
Two channels
1. RapidAPI Marketplace (existing customers)
Call https://api.qr-branding.com with your RapidAPI proxy secret. AI endpoints take your own LLM key, or use the Managed endpoint, which needs none. No change from how the original Signet QR API worked.
2. Consumer credit packs (new)
Buy a pack at /pricing. Your AI endpoints use server-side LLM keys (Groq / Gemini / OpenAI), and credits are deducted per successful generation. The front-end builder consumes this channel transparently.
Endpoints
| Method | Path | Purpose |
|---|---|---|
POST | /api/qr/generate | Render a QR from an explicit QrConfig. |
POST | /api/qr/ai/generate | Marketplace AI — bring your own LLM key. |
POST | /api/qr/ai/generate-managed | Marketplace AI — Managed, no LLM key needed. |
POST | /api/qr/ai/generate/server | Consumer AI — server-side LLM key, credit-counted. |
GET | /api/qr/templates | List the 118 pre-baked templates (optionally ?category=…). |
POST | /api/qr/templates/{templateId} | Render a QR using a template id with optional overrides. |
POST | /api/qr/content/wifi | Helper: build a WiFi QR payload string. |
POST | /api/qr/content/vcard | Helper: build a vCard payload string. |
POST | /api/qr/content/geo | Helper: build a geolocation payload string. |
GET | /api/qr/ai/providers | List supported LLM providers + models. |
GET | /api/ping | Health check (anonymous). |
Auth headers
RapidAPI
X-RapidAPI-Proxy-Secret: <secret>
Internal BFF (consumer site)
X-Internal-Service-Secret: <secret>
X-Internal-Customer-Id: <customer id>
X-Internal-Ts: <unix seconds>
X-Internal-Signature: <HMAC-SHA256(signing-key, "{customerId}.{ts}")>
TTL anti-replay: 60 seconds. Used internally by the Next.js frontend — you'll never set these by hand.
Error envelope
Every non-2xx response is shape-stable:
{
"success": false,
"error": "Content length (5000) exceeds maximum allowed (4296 characters).",
"code": "CONTENT_TOO_LONG",
"field": "content"
}
field is set when the failure points at a specific input.
Rate limits
| Tier | Per minute | Notes |
|---|---|---|
| RapidAPI general | 60 | docs, ping, helpers |
| RapidAPI generation | 30 | /api/qr/generate |
| RapidAPI AI | 15 | external LLM calls |
| Consumer general | 120 | per customer id |
| Consumer generation | 60 | per customer id |
| Consumer AI | 30 | per customer id |
There are also global per-minute ceilings to protect the free Azure tier. If you hit one you get a 429 with a Retry-After header.
Output formats
png (default, base64), jpg, svg, pdf, webp. Set "responseType": "binary" to download the file directly instead of receiving base64 in JSON.