Skip to main content
PUT
Update a QR code (full replace)

Behavior / Notes

  • Use this endpoint to update mutable fields such as name, info, pattern_info, expiry settings, geo-fencing, lead capture, password, and other advanced toggles.
  • Fields that are immutable after creation: category, qr_type, custom_domain. Attempting to change them will return a validation error.
  • PUT replaces the mutable fields you submit — only include fields you want changed. (If your client supports PATCH, prefer it for partial updates; otherwise send only the fields you intend to update.)
  • Validate new info payloads with POST /qr/validate-info/ before updating to avoid broken landing pages.

Request Body — Updatable Fields

The following fields may be included in the JSON request body. Only include fields you want to change. Common / Editable fields
Tip: Set lead_list: null to remove the lead list association.

Examples

Update QR Code Name

Update QR Code Content

Update Advanced Features

Update Geo-fencing Configuration

Update Lead List

Remove Lead List

Immutable-field errors

If an attempt is made to modify an immutable field (category, qr_type, custom_domain), the API will return a validation error describing the immutability.

Best Practices & Recommendations

  • Validate before updating: Use POST /qr/validate-info/ to confirm info payload correctness.
  • Sanitize HTML: Any HTML fields (expire_on_text, high_accuracy_geo_fencing_config.displayText) should be sanitized to prevent XSS on landing pages.
  • Minimize update payloads: Send only the fields you intend to change to avoid accidental overwrites.
  • Audit & versioning: Log update operations (who changed what and when) if your workflow requires auditability.
  • Plan entitlements: Confirm advanced features (geo-fencing, expiry, custom domains, lead capture) are enabled in the account plan before updating.
  • Test scanning: After UI/design changes (pattern_info), test scanning across devices and apps to ensure scannability.

Authorizations

Authorization
string
header
required

Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: YOUR_API_KEY. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.

Path Parameters

qrid
string
required

Response

200

QR code updated