QR code API webhooks log and GA4
SmartQRCode editorial · Updated October 2026
A qr code api webhooks log is two account-side surfaces: outbound HTTPS posts you verify, and an activity log people on the team can read. There is no qr.scanned event. GA4 forwarding sits beside them for scan-shaped data without names. A Canva static file still wins when you will never edit or count.
What a qr code api webhooks log is for
Verify hmac signature over timestamp body. There is no qr.scanned event. Register https endpoints only. Keep the activity log readable by members.
CRUD is request-response. Webhooks are the other direction: your server learns that a code was created, patched, or archived without polling /api/v1. The activity log is the human version of the same facts. GA4 forwarding, where it exists, is a third pipe aimed at a web property, still without scanner identity.
https endpoints only is a hard refuse. Private, loopback, and metadata addresses are refused, including names that resolve to them. The payload describes the account. It is signed over plaintext. HTTP would leak it.
no qr.scanned event is the surprise in every architecture review. Scan volume can be high. A webhook on every hop would be a denial of service you sold yourself. Use analytics GETs, exports, or GA4. See QR campaign tracking by code for the scan series and QR code API for CRUD for pulls. Governance of who wires this is enterprise QR code governance.
Paid options are $1.99, $29, $97, and $197. We do not sell an unpaid tier. Tracked QR codes, dynamic QR codes, and the website URL generator are the objects these events describe. Product launch placements are the usual reason a PIM wants qr.created.
Ten endpoints is the ceiling. An empty events list means every type, including types added later.
How to verify a signed delivery
hmac signature over timestamp body is the contract. Headers are X-SmartQR-Signature as v1=hex, X-SmartQR-Timestamp as unix seconds, X-SmartQR-Event as the type, and X-SmartQR-Delivery as a stable id.
- Read the raw body. Re-serialising JSON changes bytes and breaks the HMAC.
- Reject a timestamp more than five minutes off, or captured deliveries replay forever.
- Compute HMAC-SHA256 over timestamp, a dot, and the body. Compare to v1=.
- Dedupe on the delivery id. Retries reuse it on purpose.
- Answer 2xx within ten seconds. Acknowledge, then work. A 3xx is a failure; redirects are not followed because the target was never validated.
- Sort on created_at if order matters. Independent backoffs do not preserve sequence.
- Rotate the secret when it leaks. The full secret is returned once on create and once on rotate.
- Use the test post to check the pipe. Its type is test, so handlers do not treat it as qr.created.
User-Agent is SmartQR-Webhooks/1.0. Do not require a browser UA.
Which events fire, and which do not
qr.created: anyone or the API minted a code. qr.updated: destination, name, or status changed. qr.deleted: archived. bulk.completed: a batch finished, including with failures. domain.verified: a custom host became active. team.member_joined and team.member_removed: seats moved.
Not in the list: qr.scanned. If your SIEM diagram has a box for every camera hop, redraw it.
activity log readable by members is the parallel rule. A log only an owner can open deters nobody who already edits codes. Members still cannot rotate webhook secrets.
Country and device remain scan analytics, not webhook PII. F63 still holds.
How GA4 forwarding sits beside the log
GA4 is a scan-side integration, not an access log. It does not replace qr.updated for "who on the team changed the menu." It does not name shoppers. Use it when the web property is the system of record for campaigns. Use webhooks when your CRM must create a row when a code is minted.
If both are wired, do not double-count "conversions" by treating a webhook delivery as a scan. They are different events.
Webhook failures that disable the endpoint
Retries at 30s, 2m, 10m, 1h, 6h, 12h: seven attempts over about a day. After ten consecutive deliveries exhaust retries, the endpoint is disabled with a reason. Fix the receiver, then enable again so failure counts clear.
A handler that 301s to a new path fails. Register the final HTTPS URL.
A handler that takes thirty seconds times out. Queue inside your network.
A provider pause stops new scans and may stop some account events if the account cannot act. F91 remains. Webhooks do not keep a dead resolver alive.
How to build a receiver that will not disable itself
Answer 2xx fast. Persist the delivery id, then work. If you process the job inline and your CRM is slow, you time out, retry, and eventually disable the endpoint after ten exhausted deliveries. The account then looks "quiet" while codes are still being minted.
Never follow a redirect in your handler logic that you also return as a 3xx to the delivery. 3xx is already a failure. Register the final URL.
Verify HMAC on the raw body. Pretty-printing the JSON in a log line and then hashing the pretty copy is a private outage.
Do not subscribe mentally to qr.scanned. If you need scan volume, poll analytics or use GA4 forwarding. A qr code api webhooks log that you secretly wanted as a clickstream will disappoint you on day one, which is cheaper than disappointing you in a launch review.
Members can read the activity log when the CRM and the pixels disagree. Start there before rotating secrets. Owner or admin then rotate if the secret leaked, remembering it is shown once.
Version your handler. A new event type on an empty subscription list will arrive. If you listed types explicitly, you will not see new ones until you add them. If you subscribed to all types, your switch statement needs a default that 2xxs and logs. Dropping unknown types with a 500 disables the endpoint.
Store the signing secret in the same vault as the API key, with the same rotation drill. A qr code api webhooks log secret that lives in a chat log is already leaked.
Do not fire internal pages from qr.deleted without checking that archive still scans. Deleted in the event name is archived in product language. A handler that "takes the page down" on qr.deleted will fight F72.
Test deliveries use type test. Assert that in CI so a future refactor cannot send test as qr.created into production CRM logic.
Cap how many internal tools consume one endpoint. Ten endpoints is the product ceiling. One endpoint fanning out to twelve fragile scripts is how a single 500 disables everything. Split by event family if you must, and keep the HMAC verify copy-pasted from one library.
When you rotate a secret, update the vault first, then rotate in the product, then confirm a test delivery. The other order drops events into a handler that still has the old secret.
When a spreadsheet export beats a webhook
A plant needs a file on Tuesday. Export. A qr code api webhooks log is not a substitute for a frozen CSV.
One frozen poster, never edited, never counted: Canva or another free static generator. There is no event to send.
A catalogue that mints all night and a CRM that must keep up: verify signatures, refuse qr.scanned fantasies, and keep the activity log where humans look when the CRM looks wrong.
Questions this raises
qr.created, qr.updated, qr.deleted, bulk.completed, domain.verified, team.member_joined, and team.member_removed fire. There is no qr.scanned event. Scan totals stay on analytics GETs and on GA4 forwarding where that surface exists.
HMAC-SHA256 over timestamp and raw body, header v1=hex. Reject timestamps older than five minutes. Dedupe on the delivery id, which is stable across retries.
When you need a one-time plant list. A qr code api webhooks log is for systems that must react as rows change. A Canva one-off needs neither.
Retries run over about a day. After ten consecutive exhausted deliveries the endpoint is disabled with a reason. A test post does not count against that budget.
Owner or admin may change. Members may read. The activity log is readable by every member where it exists.
Keep going
The tools and playbooks this post refers to, one click away.
Make the code this post is about
$1.99 for 7 days, then a paid plan. Pick a type, brand it, and edit the destination whenever you like, even after it is printed.