> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List and create child QR Codes

> GET, POST /qr/{parent_qrid}/children/

Lists and creates GS1 **child** QR Codes — per-lot or per-serial variants of a GS1 parent.

```
GET    https://api.scanova.io/qr/{parent_qrid}/children/
POST   https://api.scanova.io/qr/{parent_qrid}/children/
Authorization: 401f7ac837da42b97f613d789819ff93537bee6a
```

<ParamField path="parent_qrid" type="string" required>
  The `qrid` of the GS1 parent QR Code.
</ParamField>

<Note>
  A child is a **lightweight variant**, not a full standalone QR Code: it shares the parent's identity and GTIN and only carries its own qualifier values (a different lot or serial). It has no detail page of its own, which is why children are managed entirely through these sub-resource endpoints.
</Note>

Creating consumes the `CHILD_QR_CODES` quota — an **independent bucket** from `TOTAL_QR_CODES` and `DYNAMIC_QR_CODES` — and requires `QR_CODE_CAN_ADD`.

### Create (POST)

<ParamField body="qualifiers" type="array" required>
  Non-empty list of `{"id": ..., "value": ...}` pairs — the GS1 application identifiers that distinguish this variant, e.g. `{"id": "10", "value": "LOT-2026-04"}` for a batch/lot.
</ParamField>

<ParamField body="dataAttributes" type="array">
  Optional additional GS1 data attributes.
</ParamField>

<ParamField body="variantLabel" type="string">
  Optional human-readable label for the variant.
</ParamField>

<ParamField body="name" type="string">
  Optional display name. Derived from the qualifiers if omitted.
</ParamField>

<Warning>
  The create body uses **camelCase** keys (`dataAttributes`, `variantLabel`) while the listing response uses snake\_case (`data_attributes`, `variant_label`). This asymmetry is intentional in the current contract — don't normalize one into the other.
</Warning>

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST "https://api.scanova.io/qr/Qz9y8x7w6v5u4t3s/children/" \
    -H "Authorization: 401f7ac837da42b97f613d789819ff93537bee6a" \
    -H "Content-Type: application/json" \
    -d '{
        "qualifiers": [
            {
                "id": "10",
                "value": "LOT-2026-04"
            }
        ],
        "dataAttributes": [],
        "variantLabel": "500ml bottle"
    }'
  ```
</RequestExample>

`source` in the response says how the child came to exist: `created` for one made here, `linked` for an existing QR Code adopted through [Link a child QR Code](/api-reference/management-api/qr/child-link). The response is not paginated.

## Related

* [Bulk-create child QR Codes](/api-reference/management-api/qr/child-bulk-create) — create many variants in one call.
* [Link a child QR Code](/api-reference/management-api/qr/child-link) — adopt an existing standalone QR Code as a variant.
* [Delete a child QR Code](/api-reference/management-api/qr/child-delete) — permanently remove one variant.
* [Check GS1 references](/api-reference/management-api/qr/gs1-references) — why a parent with children cannot be deleted.
* [QR Manager overview](/api-reference/management-api/qr/overview) — the quotas, role permissions, and Trash model shared by every endpoint in this module.
* [Management API overview](/api-reference/management-api/overview) — the auth scheme and quota rules that apply to this endpoint.


## OpenAPI

````yaml api-reference/openapi/management-api.json GET /qr/{parent_qrid}/children/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /qr/{parent_qrid}/children/:
    get:
      summary: List child QR codes
      description: >-
        GS1 child (variant) QR codes for a parent. A child is a lightweight
        variant that shares the parent's identity and GTIN but carries its own
        qualifier values (a different lot or serial, for example) — it is not a
        standalone QR code and has no detail page of its own. `scan_count` comes
        from child-specific tracking. Not paginated.
      operationId: listChildQrCodes
      parameters:
        - name: parent_qrid
          in: path
          required: true
          schema:
            type: string
          description: The `qrid` of the GS1 parent QR code.
      responses:
        '200':
          description: Child variants of this parent.
          content:
            application/json:
              example:
                - qrid: Qc3d4e5f6g7h8i9j0
                  name: 500ml bottle — LOT-2026-04
                  is_active: true
                  thumbnail: null
                  source: created
                  variant_label: 500ml bottle
                  qualifiers:
                    - id: '10'
                      value: LOT-2026-04
                  data_attributes: []
                  scan_count: 0
                  created: '2026-09-09T09:00:00Z'
                  modified: '2026-09-09T09:00:00Z'
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````