Skip to main content
The Scanova API is the programmatic interface for everything you can do in the Scanova dashboard: create and update QR Codes, manage folders and tags, read leads and form submissions, pull analytics, and manage shared users and roles. Every endpoint is served from api.scanova.io and authenticated with an API key.
This page covers the architecture that applies to every endpoint. For the full endpoint list, see the pages linked at the bottom of this page.

Getting started

1

Create an API key

While logged into the Scanova dashboard, create a key via the dashboard’s key-management UI — see Creating & managing API keys. Choose an environment — sandbox, live, zapier, or mcp — when you create it; this choice is permanent for that key and determines which plan quota is checked on every request the key makes (see below).
2

Store the key's raw value

The key value returned by the create call is the only time you’ll see it in full — store it securely. There’s no “reveal” endpoint after the fact.
3

Call the data endpoints

Send the key as the raw Authorization header value against api.scanova.io, for example GET /qr/ to list your QR Codes.

Plan quota

Every request to a data endpoint checks a plan quota tied to the key’s environment:
If a request to the data host returns 401 with the message “Your plan does not have management API quota” (or the Zapier/MCP-specific equivalents), your plan doesn’t grant that quota. Today, the canonical Pro plan does not include API access — only Free Trial, Enterprise, and Internal plans do. Contact support@scanova.io if you believe your account should have it.
sandbox is a labeling and quota concept only — it is not an isolated test environment. A key created with environment: sandbox reads and writes the same real QR Codes, folders, and leads as a live key. Don’t rely on it for throwaway test data.
A zapier/mcp key additionally only authenticates when the calling client’s User-Agent header matches its environment — a zapier key rejects requests unless User-Agent: zapier, and likewise for mcp. This is enforced independently of the quota check above.

What’s in this section

List QR Codes

GET /qr/ — the core data endpoint most integrations start with.

Create a QR Code

POST /qr/ — the core data endpoint most integrations start with.
See the sidebar for the full list, including retrieving/updating/deleting a single QR Code, downloading QR Code images, and browsing the trash.