Free
QR Code Generator
Dynamic QR codes with scan analytics, webhooks, batch API, and EU Digital Product Passport (DPP) for battery + textile — live EU compliance checks (AGEC/ESPR) before you save. Deploy on Cloudflare's global edge in seconds.
const qr = await qr3.codes.create({ content: "https://qr3.app/start", style: { dots: "rounded", color: "#F7901E" }, tracking: true, metadata: { campaign: "launch_26" } });
const qr = await qr3.codes.create({ content: "https://qr3.app/start", style: { dots: "rounded", color: "#F7901E" }, tracking: true, metadata: { campaign: "launch_26" } });
Everything you need to ship fast
From a simple URL QR to enterprise-grade Digital Product Passports — one API, one SDK, one CLI.
API-first
REST API with Zod validation, RFC 7807 errors, and OpenAPI docs. Rate-limited, versioned, and production-ready.
Learn more north_east qr_code_2Dynamic QR codes
Change the destination URL without reprinting. A/B testing, geo-redirect, and expiry built in.
Learn more north_east insightsScan analytics
Real-time scan tracking: country, city, device, OS, browser. Data stays on your infrastructure.
Learn more north_east verifiedEU Digital Product Passport
GS1 Digital Link resolver + DPP builder for battery and textile. Live validator for the EU battery regulation, French AGEC, and ESPR — errors visible before you save.
Learn more arrow_forward terminalCLI & SDKs
TypeScript SDK & CLI available now — Python, Go & PHP coming soon. MCP server for AI agents.
Learn more north_east shieldPrivacy-first
GDPR-compliant: IPs are SHA-256 hashed at the edge. Data export and erasure APIs included.
Learn more arrow_forward branding_watermarkQR code with logo
Embed your own logo in the center of the QR code. Error correction is auto-upgraded to ECC H so it stays reliably scannable — as SVG and PNG.
Learn more north_eastSecure by default
QR phishing (“quishing”) is a growing attack vector. qr3.app protects your users on multiple layers — automatically, no configuration required.
URL scan on creation
Every URL is checked against the Google Web Risk API before activation. Malicious URLs are rejected.
ActiveContinuous rescanning
All active codes are re-checked every 24 hours. Compromised codes pause automatically.
ActiveReal-time validation API
POST /v1/scan/validate integrates into scanner apps or e-mail gateways. Enterprise plan.
Abuse reporting
Anyone can flag a suspicious code via POST /v1/report — temporary suspension is instant.
Redirect transparency
The redirect worker adds an X-QR3-Scan-Status: safe header to every response.
Cloudflare edge protection
WAF, DDoS mitigation and bot management across 300+ locations. <10 ms latency worldwide.
ActiveResponsible disclosure
Please report vulnerabilities to [email protected]. We follow a 90-day responsible disclosure policy.
AI-native from day one
qr3.app ships with a full MCP server. Your AI agents can create, update, and analyze QR codes without writing a single line of code.
Requires an MCP client with secure custom HTTP-header support.
Endpoint: https://mcp.qr3.app/mcp Authorization: Bearer <API_KEY> Store the key in your MCP client's secure credential store — never in a repository.
Simple, transparent pricing
Start free. Scale when you're ready.
Free
For personal projects and prototypes.
- check Dynamic QR codes
- check SVG + PNG export
- check Basic analytics
- check API access
Pro
For professional developers and small teams.
- check Everything in Free
- check Webhooks
- check PDF export
- check Batch API (500)
Business
For growing teams with advanced needs.
- check Everything in Pro
- check Batch API (1,000)
- check Organizations & Workspaces
- check Audit logs
- check Priority support
Agency
For agencies and enterprise deployments.
- check Everything in Business
- check Custom domains
- check 50 workspaces
- check SLA 99.9%
Latest articles
Hands-on writing on DPP, QR codes and compliance — AI-researched, editorially reviewed.

ISO/IEC JTC 5: Preparing DPP Architecture for Interoperability
ISO/IEC JTC 5 is shaping an international DPP framework. What its early work means today for data models, roles and integration boundaries.

DPP Registry: Setting Up Verified Economic Operators and Access Roles
The DPP Registry Regulation makes identity and authority prerequisites for reliable registrations. A practical guide to roles, mandates and audit trails.

Digital Circularity Vehicle Passport: What Manufacturers Should Prepare for 2032
EU Regulation 2026/1738 introduces a digital circularity vehicle passport from 2032. How manufacturers can structure data, references and access now.
Frequently asked questions
Can I attach several datasheets to one QR code?
Yes. Upload one or more files to a code and turn on landing-page mode — a scan then opens a hosted page with all of that code's documents, instead of a single redirect.
Can I change where a code points after it's printed?
Yes. Dynamic codes keep the same printed QR forever; you can change the destination (or its files) anytime, and every future scan follows the new target.
In which formats can I download QR codes?
PNG for screens, plus vector SVG, PDF and EPS for print and professional layouts — straight from the dashboard.
Can I create many codes at once?
Yes. Import a CSV or Excel file (up to 1000 rows per import); each row becomes a code, and any rows that need fixing come back in a downloadable report.
Can I host my files (PDFs) at qr3?
Yes. Files you upload are hosted by qr3; public files get a stable link and can appear on a code's landing page, while private files stay restricted.
Can my team get their own logins with roles?
Yes. Invite members and assign Administrator, Editor, Contributor or Viewer. Everyone sees the workspace's codes; Editors and Admins have full control, Contributors create and edit but cannot delete, and Viewers are read-only.
What happens when I reach a plan limit?
You see your usage in the dashboard and get warning emails at 80, 90 and 100% of your monthly scans. Higher plans raise the limits for codes, scans and team seats.
Can I export my scan statistics?
Yes. Export a code's scans as CSV or XLSX for the last 7, 30 or 90 days. For privacy, visitor IPs are never included.