Use the QRCodeTransfer API

Last updated

Availability depends on your plan or configuration

What to do

Read the API documentation before creating credentials. Sign in to the intended workspace and open API & webhooks with owner or administrator access. API eligibility depends on the effective workspace plan; a visible menu does not bypass that requirement.

Create a named key and choose read-only access unless writes are needed. Copy the one-time secret to a secure server-side store. Use the documented Bearer authentication, workspace routes and request fields; never publish the key in browser code, printed URLs or shared screenshots.

Start with a permitted read and check the returned workspace. Then test the intended write using valid input and inspect its saved asset. Allowances, immutable printed fields, state rules and idempotency still apply to API requests. A key cannot claim another workspace by changing a URL.

Revoke unused or exposed credentials. Webhooks require Business Plus, an allowed HTTPS endpoint and appropriate delivery checks; private or local destinations are rejected. Check documented responses and retries rather than treating key creation as proof that every external integration has been configured.

Open this feature
Help