QR infrastructure · privacy-first

QR codes that don't leak.

Package private digital cards, revocable redirects, bulk QR campaigns, scan analytics, and webhook automation into a QR business your clients can trust.

Per-field AES encryption Token rotation in one call HMAC-signed webhooks Audit CSV export
QR · Spring 2026 Campaign
acme-spring-2026
API · Connected Plan · Agency Token · Active
30-day scans
2,847
Last 7 days
612
Webhooks
3 active
Bulk imports
14 this mo.
vCard field visibility
name · Public title · Public phone · Reveal required email · Reveal required address · Private
+ Create QR Bulk import Rotate token + Webhook Export audit CSV
From API to business model

Three businesses you can run on one API.

SealedQR is not one product packaged one way. It is the QR infrastructure layer behind three distinct businesses. Each maps to a different buyer and a different revenue model. The API stays the same.

Private business cards

Lawyers · Doctors · Advisors · Recruiters · Founders

Sell privacy-first vCards where sensitive contact fields are gated behind owner approval. Scanners see name and title; the rest stays hidden until you say otherwise.

  • Public profile scan page with safe fields only
  • Reveal request flow with email approval
  • Per-field visibility map (public / gated / private)
  • Token rotation revokes the URL without reprinting
  • Scan history visible to the owner

Agency QR campaigns

Marketing agencies · Print shops · Event marketers

Run client QR campaigns as a recurring service. Bulk-create dynamic QRs from CSV, track scans, route events to client systems, export audit reports for monthly billing.

  • CSV bulk upload — up to 500 rows per request
  • Campaign QR list with scan counts
  • HMAC-signed webhook events into client systems
  • Audit CSV export for client reporting
  • Token rotation when a campaign asset is recalled

Developer / API infrastructure

Developers · Internal tools · SaaS builders

Use SealedQR as the QR layer inside another product. Embed PNG and SVG endpoints, read JSON metadata and scan stats, react to events via webhooks, respect rate limits with Retry-After.

  • Personal access tokens for authenticated calls
  • Create URL QRs via POST /api/qrs
  • Embed PNG / SVG without auth (token is the boundary)
  • JSON metadata + 30-day scan stats endpoint
  • Webhook subscriptions with HMAC-SHA256 signing
Business workflow

Client order to monthly invoice — one pipeline.

Every part of the agency workflow maps to an API call or a dashboard action. There is no spreadsheet step.

01
Client order
200 store locations need menu QRs
02
Upload CSV
or call API
POST /api/qrs/bulk
03
Generate dynamic QRs
tokens minted, PNGs ready
04
Print / publish
embed PNG or SVG
05
Track scans
30-day stats endpoint
06
Rotate exposed tokens
single call, QR keeps working
07
Send webhook events
into client CRM or BI
08
Export audit report
CSV per workspace
09
Bill client monthly
recurring revenue

The revenue model is the workflow. Every step is something an agency can bill for as a recurring service line item — campaign management, reporting, token-rotation service, integration setup.

API capabilities as product features

What is actually shipped today.

Every capability below corresponds to a route or service in the codebase. If a feature is not listed, it does not exist yet. Roadmap items are tracked separately.

URL QR generation

Live

Dynamic redirect URLs via /r/{token}. Destination changeable without reprinting.

PDF QR generation

Live

Upload a PDF, get a QR that streams the file inline through a tokenized URL.

vCard QR generation

Live

MECARD payload with per-field visibility map. Sensitive fields gated by default.

PNG embed

Public

GET /api/qr/{token}.png — drop into HTML, Figma, slide decks.

SVG embed

Public

GET /api/qr/{token}.svg — vector for print.

JSON metadata

Public

GET /api/qr/{token} — title, scan count, all embed URLs.

30-day scan stats

Live

?stats=1 — daily counts for last 30 days.

Token rotation

Live

One click revokes the URL. Anyone with the old link gets a 404.

Field-level encryption

Live

vCard PII (name, phone, address, dob, email) encrypted at rest with AES-256-CBC.

Reveal request flow

Live

Scanner requests gated fields. Owner approves via email. 24-hour one-time link.

Recent scans feed

Live

Last 20 scans per QR with country, device, referer. No IPs shown.

API keys

Live

Personal access tokens via /account/api-keys. Plaintext shown once.

List owned QRs

Live

GET /api/qrs — 200 per page, newest first.

Create URL QRs via API

Live

POST /api/qrs — returns share token + embed URLs.

Bulk CSV upload

Live

POST /api/qrs/bulk — up to 500 rows. 207 Multi-Status with per-row errors.

Webhook subscriptions

Live

/account/webhooks — subscribe to events, ship payloads to your endpoint.

HMAC-SHA256 signing

Live

Every payload signed. X-SealedQR-Signature: sha256=.... Auto-disable after 20 failures.

Audit CSV export

Live

/account/audit.csv — every actor / action / target row, ready for client reporting.

Retry-After headers

Live

On 429 throttle responses, the API tells you the exact seconds to wait.

Event: qr.scanned

Webhook

Fires on every scan. Includes token, type, title, scan_count, device_type.

Event: token.rotated

Webhook

Fires when a QR token is rotated. Includes previous and new tokens.

Event: plan.changed

Webhook

Fires on Stripe subscription lifecycle: activated, canceled, downgraded.

Event: reveal.requested

Webhook

Fires when a scanner submits a reveal request on a vCard.

Event: reveal.approved

Webhook

Fires when the owner approves a reveal request. Includes one-time grant link.

Revenue model

Four ways to sell the same API.

The pricing maps to the buyer. Free anchors product-led acquisition. Pro Identity is the privacy-buyer impulse purchase. Agency tiers are recurring infrastructure with operational features. Prices below are monthly.

Free

Lead capture + product-led acquisition
$0/mo
  • 5 QRs across URL / PDF / public vCard
  • Owner scan counts
  • AES encryption at rest by default
  • 1 workspace
Start free
Most popular for individuals

Pro Identity

For individuals needing private business cards
$9/mo
  • Private vCards by default
  • Per-field reveal controls
  • Reveal request workflow
  • Token rotation
  • 30-day analytics + recent scans feed
  • 25 QRs · 1 workspace
Go private

Agency

For agencies selling QR campaigns to clients
$99/mo
  • Everything in Pro Identity
  • API keys
  • Bulk CSV upload
  • Signed webhook subscriptions
  • Audit CSV export
  • 5 client workspaces
Start Agency

Agency+

For larger agency programs
$299/mo
  • Everything in Agency
  • Unlimited client workspaces
  • Elevated rate limits
  • Branded redirect domains soon
  • White-label scan pages soon
  • Quarterly review call
Start Agency+
Live business demo

The product surfaces, sketched.

Four views from the same API: create a QR, run a bulk campaign, wire a webhook, export an audit log. Forms below are marketing previews; the real flows behind them live under your account.

Create a single QR

What the API call looks like

# POST /api/qrs curl -X POST https://qrgenerator.macinternetservices.com/api/qrs \ -H "Authorization: Bearer $KEY" \ -H "Content-Type: application/json" \ -d '{"url":"https://acme.com/spring-promo","title":"acme-spring-2026"}' # → 201 Created # { "share_token": "yGq7YO2mWqZ...", # "urls": { "png": "...", "svg": "...", "info": "...", "redirect": "..." } }

Bulk upload — 200 codes in one call

CSV upload to POST /api/qrs/bulk. Capped at 500 rows. Returns 207 Multi-Status when any row fails.

CSV preview

urltitle
https://acme.com/store/1001Store 1001 menu
https://acme.com/store/1002Store 1002 menu
https://acme.com/store/1003Store 1003 menu
https://acme.com/store/1004Store 1004 menu
… 196 more rows

Result · 207 Multi-Status

RowStatusDetail
2-197Created196 codes minted
198Invalid URLMissing https://
199Missing titleTitle cannot be empty
200-201Created2 codes minted
202Quota exceededPlan limit reached, remainder skipped
198 created 2 failed 1 quota

Webhook automation

Subscribe to events on /account/webhooks. Every payload is HMAC-SHA256 signed. Auto-disable after 20 consecutive failures.

# Request headers POST /sealedqr-events HTTP/1.1 Host: acme-crm.example.com Content-Type: application/json User-Agent: SealedQR-Webhook/1.0 X-SealedQR-Event: qr.scanned X-SealedQR-Signature: sha256=8a4f3b...e91c X-SealedQR-Delivery-Id: dlv_01HZX... # Body { "event": "qr.scanned", "data": { "token": "yGq7YO2mWqZ...", "type": "url", "title": "acme-spring-2026", "scan_count": 2847, "device_type": "mobile" } }

Audit / export

Every administrative action lands here. Export the whole log per workspace as CSV for client reporting.

TimestampActorActionTargetDetail
2026-06-07 14:22:08rodney@acmetoken.rotatedacme-spring-2026previous: …4f2 · new: …e91c
2026-06-07 13:50:31systemqr.scannedstore-1042device: mobile · scan #1,283
2026-06-07 13:11:02rodney@acmewebhook.createdacme-crm.example.comevents: qr.scanned, token.rotated
2026-06-07 11:04:55systemsubscription.activatedrodney@acmeplan: Agency
2026-06-06 22:18:00scannerreveal.requestedkowalski.vcardscanner: heather@…
2026-06-06 22:20:14kowalski@firmreveal.approvedkowalski.vcardfields: phone, email
Export audit CSV (marketing preview) Real exports live at /account/audit.csv.
Common questions

What people ask before signing up.

What does "encrypted at rest" mean here, specifically?

vCard PII fields — name, address, phone, date of birth, email — are AES-256-CBC encrypted per row before they reach MySQL. The decryption key lives in an environment variable on the application server. If our database is dumped, the contents are ciphertext.

What happens when I rotate a token?

The old share_token stops working immediately. Anyone with the prior URL gets a 404. The printed QR keeps working because the new token can be re-linked to it. Useful when a campaign asset gets recalled or when a vCard owner changes jobs.

Can I move my data out?

Yes. Account export returns everything we have about you — profile, QRs, scan events, audit log — as JSON. No queue, no support ticket.

How does an agency bill clients with this?

Each client lives in a workspace. The audit CSV export and the scan stats endpoint produce per-workspace reports you can attach to a monthly invoice. The agency tier rolls up all client workspaces under one subscription you control.

Is the Free tier going to stay free?

Yes. Revenue comes from Pro Identity and the Agency tiers. The Free tier exists for product-led acquisition; it will not be cut off or time-limited.

Where does SealedQR run?

A single Docker host that we operate at dev.macinternetservices.com in the US. Self-hosted Docker is available for buyers who need the data inside their own infrastructure.