Skip to main content
POST
Issues a short-lived token that lets the landing app render this QR Code’s unpublished draft without a login — the “Preview” button in the editor.
string
required
The QR Code’s qrid.
Takes no request body.
The token is a JWT with a short lifetime — about 3600 seconds by default. Mint it when the user opens a preview, not ahead of time, and never embed it in anything long-lived: anyone holding it can read the unpublished draft.
A QR Code that has no url_hash yet returns 400 — there is no URL to preview against until one is assigned.

Authorizations

Authorization
string
header
required

Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.

Path Parameters

qrid
string
required

The QR code's qrid — the opaque public identifier returned by the list endpoint, not the numeric id.

Response

A preview token and the URL to use it against.