Skip to content
UseQR
ESC

Jump to

↑↓MOVE↵OPEN50 places

Security & privacy

Password-protected and expiring QR links

A QR image cannot enforce a password, expiry date or scan limit. It carries readable data that can be copied. Put authentication, access rules and expiry checks at the destination service, then encode its stable URL. UseQR can create that URL code; it does not host protected pages or enforce access policies.

View as MarkdownPaste this page into any AI assistant. It is plain, portable Markdown.

Protect the resource rather than the image

A code on a conference poster or staff badge is visible to anyone who photographs it. Encoding a password beside a document link gives the viewer both pieces. Obscuring the artwork makes the code harder to scan without creating meaningful access control.

Instead encode a URL for an application that checks access before showing the document or performing the action. For staff resources, use your existing identity provider. For customer resources, use an appropriate authenticated portal.

Decide what expiry means

Expiry can mean the offer ends, a download is no longer available, or a ticket cannot be redeemed. Those rules belong to the application. When a request arrives, it checks the current policy and shows a clear explanation if access has ended.

The QR image remains readable after expiry. A printed date is helpful for users, but does not prevent a copied payload from being opened. Use an owned stable URL if you need to change the expiry message without replacing the artwork.

Avoid embedding a long-lived login token, recovery code or secret into distributed artwork. An unguessable URL can still be forwarded or photographed. Where a link grants access by possession, treat it as a credential and design revocation and expiry within the destination system.

Use the URL generator for the resource's entry page. For sensitive URLs, prefer the browser tool over the hosted API: API requests send the payload to the server. Verify the final image without assuming that a successful decode proves the access policy works.

Test as each intended audience

Try the page while logged out, as an authorised user and as a user without permission. Test the expired state as well. A correct permission check needs a helpful denial screen, a contact route and a text fallback for visitors who cannot scan.

UseQR does not offer a password gate, hosted file storage or a timed redirect service. Those are destination features, not properties of static QR codes.

FAQ

Can I make a static QR code stop scanning tomorrow?

No. You can change what the destination permits tomorrow, but the image still decodes.

Is a hard-to-guess URL enough for confidential documents?

Possession of the URL can grant access in some systems. For confidential material, use the destination's authenticated access controls and test them.

Try it: free, no signup