Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

QRCodeKIT

REMOTE · MCP.V2.QRCODEKIT.COM · SCANNED SEP 29

Branded short links, instant page & file hosting, and dynamic QR codes with unified analytics.

68 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability82
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3021 tokens (~177/item across 17 items; 14 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
  • Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the QRCodeKIT MCP server?

QRCodeKIT is a hosted endpoint at https://mcp.v2.qrcodekit.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.v2.qrcodekit.com

# add to Claude Code
claude mcp add --transport http com-qrcodekit-qrcodekit 'https://mcp.v2.qrcodekit.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-qrcodekit-qrcodekit": {
      "url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-qrcodekit-qrcodekit": {
      "type": "http",
      "url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-qrcodekit-qrcodekit]
url = "https://mcp.v2.qrcodekit.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-qrcodekit-qrcodekit": {
      "type": "remote",
      "url": "https://mcp.v2.qrcodekit.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-qrcodekit-qrcodekit --url 'https://mcp.v2.qrcodekit.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-qrcodekit-qrcodekit:
    url: "https://mcp.v2.qrcodekit.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-qrcodekit-qrcodekit": {
      "Transport": "http",
      "Url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-qrcodekit-qrcodekit -t streamable-http -u 'https://mcp.v2.qrcodekit.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-qrcodekit-qrcodekit": {
      "type": "http",
      "url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 66

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcp.v2.qrcodekit.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=v2.qrcodekit.com CN=Amazon RSA 2048 M04,O=Amazon,C=US 20 Sept 2026 5 Apr 2027 RSA 2048 SHA256-RSA 7f7d6f0b8acc3de3d6d0fd99fde13d7
SANs: v2.qrcodekit.com, *.v2.qrcodekit.com
CN=Amazon RSA 2048 M04,O=Amazon,C=US (CA) CN=Amazon Root CA 1,O=Amazon,C=US 23 Aug 2022 23 Aug 2030 RSA 2048 SHA256-RSA 773124f2a952e3ed18a58bdb85d1bc0ce5f27
CN=Amazon Root CA 1,O=Amazon,C=US (CA) CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US 25 May 2015 31 Dec 2037 RSA 2048 SHA256-RSA 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.v2.qrcodekit.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
qrcodekit.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.v2.qrcodekit.com/mcp Verified 200
http (plaintext) http://mcp.v2.qrcodekit.com/mcp HTTPS enforced 301 https://mcp.v2.qrcodekit.com:443/mcp
MCP tools · 14 exposed · ~2,714 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
create_file_upload_session ~131

Widget-only helper: mint a one-time upload session so the file upload form can send the selected file to QRCodeKIT without exposing credentials. Not intended for direct use; prefer 'Upload a File → Get a Link & QR'.

NameTypeReqDescription
filenamestringyesOriginal filename of the selected file.
mime_type––MIME type reported by the browser for the selected file.
size_bytesintegeryesSize of the selected file in bytes. Must be at most 50 MB.
typologystringyesUse 'file' for an arbitrary file or 'pdf' for a PDF.
NameTypeReqDescription
expires_atstringyesISO-8601 timestamp when the session expires.
field_namestring–Multipart field name for the uploaded file.
max_bytesintegeryesMaximum accepted upload size in bytes.
methodstring–HTTP method the widget must use for the upload.
session_idstringyesOpaque backend upload-session identifier.
upload_urlstringyesSingle-use URL the widget posts the file to (multipart form data).

No examples provided.

delete_link ~83

Move an existing QRCodeKIT link and its QR code to the active account's trash. Use this only when the user asks to delete, remove, or discard a specific link. Reversible from the QRCodeKIT web app. Resolve the exact qr_id before deleting when the target is ambiguous.

NameTypeReqDescription
qr_idstringyesStable QRCodeKIT identifier for the link.
NameTypeReqDescription
deletedbooleanyesWhether the QR was moved to trash.
qr_idstringyesStable QRCodeKIT identifier for the QR moved to trash.

No examples provided.

get_link_stats ~347

Retrieve analytics for the whole QRCodeKIT account or for one link. Reports total, unique, and repeat visits, unique-visitor ratio, activity over time, and — when the account plan supports advanced analytics — breakdowns by country, city, device, operating system, and browser. Account-wide results also include the number of links and the top links ranked by lifetime visits. Use this when the user asks about QR scans, short-link clicks, campaign performance, audience location, devices, trends, comparisons, or top-performing links. Every visit to the short URL is counted, so link clicks and QR scans are combined: one campaign can live in a printed QR, an Instagram bio, and an email and report in one place. Select a link by qr_id, slug, or part of its title via `qr`; omit it for the whole account. Defaults to the last 30 days; the interval can be auto, hourly, daily, weekly, or monthly. The structured result contains the full tables for answering questions about the data.

NameTypeReqDescription
end_date––Last day of the stats window (YYYY-MM-DD). Defaults to today.
intervalstring–Time-series bucket size: 1h, 1d, 1w, or 1M. Use 'auto' (default) to pick a sensible bucket from the range length.
qr––Optional link to deep-dive into: the QRCodeKIT qr_id, the short-link slug, or (part of) the link title. Omit for account-wide stats.
start_date––First day of the stats window (YYYY-MM-DD). Defaults to 29 days before end_date.
NameTypeReqDescription
advanced_stats_availableboolean–False when the plan does not include advanced analytics breakdowns.
browsersarray––
citiesarray––
countriesarray––
devicesarray––
end_datestringyesLast day of the stats window (YYYY-MM-DD).
intervalstringyesTime-series bucket size: 1h, 1d, 1w, or 1M.
notice––Human-readable note about limits or missing data, if any.
operating_systemsarray––
qr––The QR the stats belong to when scope is 'qr'.
qr_count––Account scope only: number of QRs covered by the stats.
scopestringyes'qr' for a single QR deep-dive, 'account' for all QRs in the account.
start_datestringyesFirst day of the stats window (YYYY-MM-DD).
summary–––
time_seriesarray––
top_qrsarray–Account scope only: QRs ranked by lifetime visit totals.

No examples provided.

host_file ~187

Upload and host a local PDF, image, document, spreadsheet, or other file, and get a permanent public short link plus a downloadable dynamic QR code that opens or downloads it. Use this when the user wants to publish or share an attached PDF or file — a PDF menu, brochure, catalog, CV, ticket, presentation, or any document — without a separate file-hosting account. QRCodeKIT copies the attachment to its own asset storage and validates PDFs as real PDF documents. When `qr_id` is provided, replace the hosted file while preserving the existing public URL and printed QR code.

NameTypeReqDescription
file–yesAttached file to host — PDF or any other type — stored as a QRCodeKIT asset before creating the link.
qr_id––Optional QRCodeKIT identifier for updating an existing link instead of creating one.
titlestringyesDisplay title for the link.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

list_links ~150

Return the account's QRCodeKIT links as structured data: title, destination or hosted content, short URL, slug, QR image download URLs, timestamps, and lifetime visits. Lifetime visits combine short-link clicks and QR scans. Use this when the assistant needs to search, filter by link type, compare, inspect, or process existing links programmatically. Use show_links instead when the user asks to see, show, display, preview, or download their links or QR codes.

NameTypeReqDescription
limitinteger–Maximum number of links to return from the active account.
typologystring–Link typology internal name to filter by. Use 'all' or omit this field to return all typologies.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

render_file_upload_qr_form ~228

Open an interactive form for the user to upload a file or PDF from their device and get a permanent short link plus a downloadable dynamic QR code. Use this on Claude and other MCP hosts that cannot pass an attached file directly, whenever the user wants to share or host a PDF, menu, brochure, CV, ticket, or other file by link or QR. The form uploads the file to QRCodeKIT and saves the link; when `qr_id` is provided, it replaces the file of an existing link while preserving its short URL and QR code.

NameTypeReqDescription
qr_id––Optional QRCodeKIT identifier when updating an existing QR instead of creating one.
title––QR title used when the upload is saved; the form has no title input. Always pass a sensible title from the conversation; when updating an existing QR, pass that QR's current title. Defaults to the up…
typologystring–Initial file typology hint for the form heading. The final typology is inferred from the uploaded file's extension, so this is only a default.
NameTypeReqDescription
max_bytesinteger–Maximum accepted upload size in bytes, enforced client-side for UX.
qr_id––Stable QRCodeKIT identifier when the widget updates an existing QR.
title––QR title used when the upload is saved. Falls back to the uploaded filename.
typologystring–Initial file typology for the form.

No examples provided.

save_app_store_link ~210

Create a device-routing smart link and dynamic QR code for a mobile app: the same short link sends iPhone users to the Apple App Store and Android users to Google Play. Use this for 'download our app' campaigns in print, ads, websites, or link-in-bio pages. An app name and at least one store URL (iOS or Android) are required; an icon URL is optional. When `qr_id` is provided, update the app destinations while preserving the existing short link and QR code.

NameTypeReqDescription
android_url––Optional Google Play URL, such as https://play.google.com/store/apps/details?id=com.example.
app_namestringyesApp name shown on the App Store QR landing page.
image_url––Optional app icon image URL.
ios_url––Optional Apple App Store URL, such as https://apps.apple.com/app/example/id123.
qr_id––Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

save_email_link ~167

Create a short link and dynamic QR code that opens a pre-filled email with a recipient, required subject, optional body, and optional CC recipients. Use this for 'contact us' flows, support or quote requests, RSVPs, feedback, reservations, or other email calls to action. When `qr_id` is provided, update the email details while preserving the existing short link and QR code.

NameTypeReqDescription
bodystring–Optional pre-filled email body.
cc––Optional CC email addresses.
email_addressstringyesRecipient email address for the email QR.
qr_id––Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
subjectstringyesPre-filled email subject.
titlestringyesDisplay title for the link.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

save_file_url_qr ~210

Create or update a permanent short link and dynamic QR code for a file or PDF that is already hosted at a public URL. Use this as a fallback when the host cannot pass an attached file; prefer host_file for local or host-native attachments. When `qr_id` is provided, update the file destination while preserving the existing short link and QR code. Also used as the finalizer step by the in-chat upload form.

NameTypeReqDescription
asset_iri––Optional QRCodeKIT asset IRI returned by an earlier upload.
file_urlstringyesAlready-hosted public file URL, preferably a QRCodeKIT asset URL.
original_filename––Original filename to show for the download. Defaults to 'file'.
qr_id––Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
titlestringyesDisplay title for the QR.
typologystringyesUse 'file' for an arbitrary file or 'pdf' for a PDF.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

save_html_file_qr ~264

Publish a single-page static HTML site live on the web and get a permanent public URL and shareable link, plus a downloadable dynamic QR code that opens it. Use this when the user asks to create, publish, deploy, host, share, or put online a landing page, one-pager, business page, digital menu, event page, portfolio, product page, campaign page, or microsite — especially when they do not have a website or hosting provider. No separate hosting account, build step, or deployment token is required. Accepts one complete HTML document up to 6 MB: a single file, not a multi-page site. When `qr_id` is provided, update the hosted page in place while preserving its public URL and printed QR code.

NameTypeReqDescription
htmlstringyesComplete HTML document for a static page, such as an AI-generated landing page or microsite, to publish at a public QRCodeKIT-hosted URL and share through the returned shortlink. Maximum size is 6 MB…
qr_id––Optional QRCodeKIT identifier for updating an existing hosted HTML page in place while preserving the same public URL and QR code.
titlestringyesHuman-readable title for the hosted page.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

save_short_link ~258

Create a branded short link and dynamic QR code for an existing website URL, with an optional custom slug (e.g. qrkit.co/summer-sale). Use this when the user already has a destination URL and wants to shorten or brand it, track visits, or get a QR code for it: every link includes a scannable QR code that opens the same destination, and clicks and scans are tracked together in one analytics dashboard. When `qr_id` is provided, change the destination while preserving the existing short URL and printed QR code. Use set_link_slug instead when the user wants to rename the slug of an existing link.

NameTypeReqDescription
destination_urlstringyesDestination URL the short link and QR code redirect to.
qr_id––Optional QRCodeKIT identifier for updating an existing link instead of creating one.
short_code––Optional custom slug for the new short link, such as 'summer-sale' — the branded part of the short URL (qrkit.co/summer-sale). Letters, digits, dots, hyphens, and underscores only; must be unique wit…
titlestringyesDisplay title for the link.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

save_whatsapp_link ~164

Create a short link and dynamic QR code that opens a WhatsApp conversation with a phone number in international format and an optional pre-filled message. Use this for 'chat with us' or contact buttons, customer support, reservations, sales enquiries, printed signage, business cards, or link-in-bio pages. When `qr_id` is provided, update the phone number or message while preserving the existing short link and QR code.

NameTypeReqDescription
messagestring–Optional pre-filled WhatsApp message.
phone_numberstringyesWhatsApp phone number with international country code, such as +12025550123.
qr_id––Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
titlestringyesDisplay title for the link.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

set_link_slug ~182

Change the custom slug (short code) of an existing QRCodeKIT short link, for any link type — e.g. turn qrkit.co/x7Ab9c into qrkit.co/summer-sale. The link keeps its identity and analytics. Use this only when the user explicitly wants to rename the short URL; to change a destination, use the corresponding save tool instead. WARNING: warn the user that the previous short URL stops redirecting and the QR image is regenerated, so any printed or shared copies of the old QR must be replaced.

NameTypeReqDescription
qr_idstringyesStable QRCodeKIT identifier for the link.
short_codestringyesNew slug for the short link, such as 'my-campaign-2026'. Letters, digits, dots, hyphens, and underscores only. Must be unique within the short-link domain.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

show_links ~133

Display the account's QRCodeKIT links in an interactive gallery: short URL, QR image, combined click-and-scan totals, and download actions. Available QR assets may include SVG, PNG, PDF, and EPS. Use this when the user asks to see, show, preview, display, or download their links or QR codes. When qr_id is provided, show only that link; otherwise show links from the active account.

NameTypeReqDescription
limitinteger–Maximum number of links to render when qr_id is absent.
qr_id––Optional QRCodeKIT identifier for showing a single link instead of the gallery list.
NameTypeReqDescription
itemsarray–QR codes visible to the active account.

No examples provided.

Common questions

What is the QRCodeKIT MCP server?

QRCodeKIT is an MCP server listed in the public MCP registry as com.qrcodekit/qrcodekit. Branded short links, instant page & file hosting, and dynamic QR codes with unified analytics. This page covers its hosted endpoint (https://mcp.v2.qrcodekit.com/mcp).

Is the QRCodeKIT MCP server safe to use?

QRCodeKIT scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the QRCodeKIT MCP server expose?

QRCodeKIT exposes 14 tools: list_links, show_links, get_link_stats, save_short_link, save_html_file_qr, and 9 more. Their descriptions and schemas cost roughly 2,714 tokens of context every time the server is loaded.

Does the QRCodeKIT MCP server require authentication?

No. We connected to QRCodeKIT without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the QRCodeKIT MCP server still maintained?

QRCodeKIT is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.