# QRCodeTransfer API

Base URL: https://qrcodetransfer.com/api/v1/

Keep API credentials on your server. Send Authorization: Bearer YOUR_API_KEY.
Each key belongs to one workspace and has read/write scopes.

## Assets

GET /workspaces/{workspace}/assets?kind=QRCODE&page=1&pageSize=20
POST /workspaces/{workspace}/assets
GET /workspaces/{workspace}/assets/{id}
PATCH /workspaces/{workspace}/assets/{id}
DELETE /workspaces/{workspace}/assets/{id}
POST /workspaces/{workspace}/assets/{id}/actions/{publish|pause|resume|restore|close}

Example JSON:
{"kind":"QRCODE","name":"Campaign","payload":{"type":"LINK","url":"https://example.com","dynamic":true}}

Kinds: QRCODE, SHORTLINK, PAGE, FORM, GS1.
Printed dynamic paths are immutable and never reassigned after deletion.
PAGE and FORM are drafts until published. Draft edits do not replace published content.

## Files

POST /workspaces/{workspace}/files (multipart file)
GET /workspaces/{workspace}/files
GET /workspaces/{workspace}/files/{id}/download

## Forms

POST /api/public/forms/{slug}/submissions
{"answers":{"field-id":"value"},"idempotencyKey":"unique-submission-id"}

## Bulk

POST /workspaces/{workspace}/bulk/preview
POST /workspaces/{workspace}/bulk/execute
Header Idempotency-Key: unique-batch-id
{"kind":"SHORTLINK","rows":[{"url":"https://example.com"}]}

## MCP

POST /api/mcp (outside the /api/v1 base path)
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json

Stateless HTTP JSON responses. JSON-RPC methods: initialize, ping, tools/list, tools/call.
Tools: qct_list_assets, qct_get_asset, qct_create_asset, qct_update_asset, qct_analytics.
Workspace and plan permissions apply; write tools require write scope.
Hosted client compatibility and direct client sign-in are not yet verified.

## Errors

Errors return code, message and optional fields.
401 authentication, 403 permission, 409 state/version/quota/conflict,
422 invalid input, 503 unavailable external service.
Public paused or blocked codes return 410.

Current integration availability is returned by GET /api/public/capabilities.
