Skip to content

API overview

The engine is published as a small HTTP API. There are two ways to authenticate.

Two channels

1. RapidAPI Marketplace (existing customers)

Call https://api.qr-branding.com with your RapidAPI proxy secret. AI endpoints take your own LLM key, or use the Managed endpoint, which needs none. No change from how the original Signet QR API worked.

2. Consumer credit packs (new)

Buy a pack at /pricing. Your AI endpoints use server-side LLM keys (Groq / Gemini / OpenAI), and credits are deducted per successful generation. The front-end builder consumes this channel transparently.

Endpoints

MethodPathPurpose
POST/api/qr/generateRender a QR from an explicit QrConfig.
POST/api/qr/ai/generateMarketplace AI — bring your own LLM key.
POST/api/qr/ai/generate-managedMarketplace AI — Managed, no LLM key needed.
POST/api/qr/ai/generate/serverConsumer AI — server-side LLM key, credit-counted.
GET/api/qr/templatesList the 118 pre-baked templates (optionally ?category=…).
POST/api/qr/templates/{templateId}Render a QR using a template id with optional overrides.
POST/api/qr/content/wifiHelper: build a WiFi QR payload string.
POST/api/qr/content/vcardHelper: build a vCard payload string.
POST/api/qr/content/geoHelper: build a geolocation payload string.
GET/api/qr/ai/providersList supported LLM providers + models.
GET/api/pingHealth check (anonymous).

Auth headers

RapidAPI

X-RapidAPI-Proxy-Secret: <secret>

Internal BFF (consumer site)

X-Internal-Service-Secret: <secret>
X-Internal-Customer-Id:    <customer id>
X-Internal-Ts:             <unix seconds>
X-Internal-Signature:      <HMAC-SHA256(signing-key, "{customerId}.{ts}")>

TTL anti-replay: 60 seconds. Used internally by the Next.js frontend — you'll never set these by hand.

Error envelope

Every non-2xx response is shape-stable:

{
  "success": false,
  "error": "Content length (5000) exceeds maximum allowed (4296 characters).",
  "code": "CONTENT_TOO_LONG",
  "field": "content"
}

field is set when the failure points at a specific input.

Rate limits

TierPer minuteNotes
RapidAPI general60docs, ping, helpers
RapidAPI generation30/api/qr/generate
RapidAPI AI15external LLM calls
Consumer general120per customer id
Consumer generation60per customer id
Consumer AI30per customer id

There are also global per-minute ceilings to protect the free Azure tier. If you hit one you get a 429 with a Retry-After header.

Output formats

png (default, base64), jpg, svg, pdf, webp. Set "responseType": "binary" to download the file directly instead of receiving base64 in JSON.