Package private digital cards, revocable redirects, bulk QR campaigns, scan analytics, and webhook automation into a QR business your clients can trust.
SealedQR is not one product packaged one way. It is the QR infrastructure layer behind three distinct businesses. Each maps to a different buyer and a different revenue model. The API stays the same.
Sell privacy-first vCards where sensitive contact fields are gated behind owner approval. Scanners see name and title; the rest stays hidden until you say otherwise.
Run client QR campaigns as a recurring service. Bulk-create dynamic QRs from CSV, track scans, route events to client systems, export audit reports for monthly billing.
Use SealedQR as the QR layer inside another product. Embed PNG and SVG endpoints, read JSON metadata and scan stats, react to events via webhooks, respect rate limits with Retry-After.
POST /api/qrsEvery part of the agency workflow maps to an API call or a dashboard action. There is no spreadsheet step.
The revenue model is the workflow. Every step is something an agency can bill for as a recurring service line item — campaign management, reporting, token-rotation service, integration setup.
Every capability below corresponds to a route or service in the codebase. If a feature is not listed, it does not exist yet. Roadmap items are tracked separately.
Dynamic redirect URLs via /r/{token}. Destination changeable without reprinting.
Upload a PDF, get a QR that streams the file inline through a tokenized URL.
MECARD payload with per-field visibility map. Sensitive fields gated by default.
GET /api/qr/{token}.png — drop into HTML, Figma, slide decks.
GET /api/qr/{token}.svg — vector for print.
GET /api/qr/{token} — title, scan count, all embed URLs.
?stats=1 — daily counts for last 30 days.
One click revokes the URL. Anyone with the old link gets a 404.
vCard PII (name, phone, address, dob, email) encrypted at rest with AES-256-CBC.
Scanner requests gated fields. Owner approves via email. 24-hour one-time link.
Last 20 scans per QR with country, device, referer. No IPs shown.
Personal access tokens via /account/api-keys. Plaintext shown once.
GET /api/qrs — 200 per page, newest first.
POST /api/qrs — returns share token + embed URLs.
POST /api/qrs/bulk — up to 500 rows. 207 Multi-Status with per-row errors.
/account/webhooks — subscribe to events, ship payloads to your endpoint.
Every payload signed. X-SealedQR-Signature: sha256=.... Auto-disable after 20 failures.
/account/audit.csv — every actor / action / target row, ready for client reporting.
On 429 throttle responses, the API tells you the exact seconds to wait.
Fires on every scan. Includes token, type, title, scan_count, device_type.
Fires when a QR token is rotated. Includes previous and new tokens.
Fires on Stripe subscription lifecycle: activated, canceled, downgraded.
Fires when a scanner submits a reveal request on a vCard.
Fires when the owner approves a reveal request. Includes one-time grant link.
The pricing maps to the buyer. Free anchors product-led acquisition. Pro Identity is the privacy-buyer impulse purchase. Agency tiers are recurring infrastructure with operational features. Prices below are monthly.
Four views from the same API: create a QR, run a bulk campaign, wire a webhook, export an audit log. Forms below are marketing previews; the real flows behind them live under your account.
CSV upload to POST /api/qrs/bulk. Capped at 500 rows. Returns 207 Multi-Status when any row fails.
| url | title |
|---|---|
| https://acme.com/store/1001 | Store 1001 menu |
| https://acme.com/store/1002 | Store 1002 menu |
| https://acme.com/store/1003 | Store 1003 menu |
| https://acme.com/store/1004 | Store 1004 menu |
| … 196 more rows | |
| Row | Status | Detail |
|---|---|---|
| 2-197 | Created | 196 codes minted |
| 198 | Invalid URL | Missing https:// |
| 199 | Missing title | Title cannot be empty |
| 200-201 | Created | 2 codes minted |
| 202 | Quota exceeded | Plan limit reached, remainder skipped |
Subscribe to events on /account/webhooks. Every payload is HMAC-SHA256 signed. Auto-disable after 20 consecutive failures.
Every administrative action lands here. Export the whole log per workspace as CSV for client reporting.
| Timestamp | Actor | Action | Target | Detail |
|---|---|---|---|---|
| 2026-06-07 14:22:08 | rodney@acme | token.rotated | acme-spring-2026 | previous: …4f2 · new: …e91c |
| 2026-06-07 13:50:31 | system | qr.scanned | store-1042 | device: mobile · scan #1,283 |
| 2026-06-07 13:11:02 | rodney@acme | webhook.created | acme-crm.example.com | events: qr.scanned, token.rotated |
| 2026-06-07 11:04:55 | system | subscription.activated | rodney@acme | plan: Agency |
| 2026-06-06 22:18:00 | scanner | reveal.requested | kowalski.vcard | scanner: heather@… |
| 2026-06-06 22:20:14 | kowalski@firm | reveal.approved | kowalski.vcard | fields: phone, email |
/account/audit.csv.
vCard PII fields — name, address, phone, date of birth, email — are AES-256-CBC encrypted per row before they reach MySQL. The decryption key lives in an environment variable on the application server. If our database is dumped, the contents are ciphertext.
The old share_token stops working immediately. Anyone with the prior URL gets a 404. The printed QR keeps working because the new token can be re-linked to it. Useful when a campaign asset gets recalled or when a vCard owner changes jobs.
Yes. Account export returns everything we have about you — profile, QRs, scan events, audit log — as JSON. No queue, no support ticket.
Each client lives in a workspace. The audit CSV export and the scan stats endpoint produce per-workspace reports you can attach to a monthly invoice. The agency tier rolls up all client workspaces under one subscription you control.
Yes. Revenue comes from Pro Identity and the Agency tiers. The Free tier exists for product-led acquisition; it will not be cut off or time-limited.
A single Docker host that we operate at dev.macinternetservices.com in the US. Self-hosted Docker is available for buyers who need the data inside their own infrastructure.