# QRCodeKIT (remote · mcp.v2.qrcodekit.com)

Branded short links, instant page & file hosting, and dynamic QR codes with unified analytics.

- Trust score: 68/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `mcp.v2.qrcodekit.com`: 68/100 (this document), [markdown](https://verifymcp.io/servers/com-qrcodekit-qrcodekit/mcp.md), [page](https://verifymcp.io/servers/com-qrcodekit-qrcodekit/mcp)

## Channel facts

- Endpoint: `https://mcp.v2.qrcodekit.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (set_link_slug).
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 82/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3021 tokens (~177/item across 17 items; 14 tools + 3 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 17/100
  - Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
  - Supports UI / widget rendering.

## Install

### How do I install the QRCodeKIT MCP server?

QRCodeKIT is a hosted endpoint at https://mcp.v2.qrcodekit.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-qrcodekit-qrcodekit 'https://mcp.v2.qrcodekit.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-qrcodekit-qrcodekit": {
      "url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-qrcodekit-qrcodekit": {
      "type": "http",
      "url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-qrcodekit-qrcodekit]
url = "https://mcp.v2.qrcodekit.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-qrcodekit-qrcodekit": {
      "type": "remote",
      "url": "https://mcp.v2.qrcodekit.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-qrcodekit-qrcodekit --url 'https://mcp.v2.qrcodekit.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-qrcodekit-qrcodekit:
    url: "https://mcp.v2.qrcodekit.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-qrcodekit-qrcodekit": {
      "Transport": "http",
      "Url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-qrcodekit-qrcodekit -t streamable-http -u 'https://mcp.v2.qrcodekit.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-qrcodekit-qrcodekit": {
      "type": "http",
      "url": "https://mcp.v2.qrcodekit.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-28 (score 67, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-26 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-25 (score 66, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 66)

First indexed and scored.

## MCP tools (14)

### `list_links` (~150 tokens)

List Links & QR Codes

Return the account's QRCodeKIT links as structured data: title, destination or hosted content, short URL, slug, QR image download URLs, timestamps, and lifetime visits. Lifetime visits combine short-link clicks and QR scans. Use this when the assistant needs to search, filter by link type, compare, inspect, or process existing links programmatically. Use show_links instead when the user asks to see, show, display, preview, or download their links or QR codes.

Input parameters:

- `limit` (integer): Maximum number of links to return from the active account.
- `typology` (string): Link typology internal name to filter by. Use 'all' or omit this field to return all typologies.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `show_links` (~133 tokens)

Show Links & QR Codes

Display the account's QRCodeKIT links in an interactive gallery: short URL, QR image, combined click-and-scan totals, and download actions. Available QR assets may include SVG, PNG, PDF, and EPS. Use this when the user asks to see, show, preview, display, or download their links or QR codes. When qr_id is provided, show only that link; otherwise show links from the active account.

Input parameters:

- `limit` (integer): Maximum number of links to render when qr_id is absent.
- `qr_id`: Optional QRCodeKIT identifier for showing a single link instead of the gallery list.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `get_link_stats` (~347 tokens)

Link & QR Analytics

Retrieve analytics for the whole QRCodeKIT account or for one link. Reports total, unique, and repeat visits, unique-visitor ratio, activity over time, and — when the account plan supports advanced analytics — breakdowns by country, city, device, operating system, and browser. Account-wide results also include the number of links and the top links ranked by lifetime visits. Use this when the user asks about QR scans, short-link clicks, campaign performance, audience location, devices, trends, comparisons, or top-performing links. Every visit to the short URL is counted, so link clicks and QR scans are combined: one campaign can live in a printed QR, an Instagram bio, and an email and report in one place. Select a link by qr_id, slug, or part of its title via `qr`; omit it for the whole account. Defaults to the last 30 days; the interval can be auto, hourly, daily, weekly, or monthly. The structured result contains the full tables for answering questions about the data.

Input parameters:

- `end_date`: Last day of the stats window (YYYY-MM-DD). Defaults to today.
- `interval` (string): Time-series bucket size: 1h, 1d, 1w, or 1M. Use 'auto' (default) to pick a sensible bucket from the range length.
- `qr`: Optional link to deep-dive into: the QRCodeKIT qr_id, the short-link slug, or (part of) the link title. Omit for account-wide stats.
- `start_date`: First day of the stats window (YYYY-MM-DD). Defaults to 29 days before end_date.

Output parameters:

- `advanced_stats_available` (boolean): False when the plan does not include advanced analytics breakdowns.
- `browsers` (array)
- `cities` (array)
- `countries` (array)
- `devices` (array)
- `end_date` (string): Last day of the stats window (YYYY-MM-DD).
- `interval` (string): Time-series bucket size: 1h, 1d, 1w, or 1M.
- `notice`: Human-readable note about limits or missing data, if any.
- `operating_systems` (array)
- `qr`: The QR the stats belong to when scope is 'qr'.
- `qr_count`: Account scope only: number of QRs covered by the stats.
- `scope` (string): 'qr' for a single QR deep-dive, 'account' for all QRs in the account.
- `start_date` (string): First day of the stats window (YYYY-MM-DD).
- `summary`
- `time_series` (array)
- `top_qrs` (array): Account scope only: QRs ranked by lifetime visit totals.

### `save_short_link` (~258 tokens)

Save Short Link

Create a branded short link and dynamic QR code for an existing website URL, with an optional custom slug (e.g. qrkit.co/summer-sale). Use this when the user already has a destination URL and wants to shorten or brand it, track visits, or get a QR code for it: every link includes a scannable QR code that opens the same destination, and clicks and scans are tracked together in one analytics dashboard. When `qr_id` is provided, change the destination while preserving the existing short URL and printed QR code. Use set_link_slug instead when the user wants to rename the slug of an existing link.

Input parameters:

- `destination_url` (string, required): Destination URL the short link and QR code redirect to.
- `qr_id`: Optional QRCodeKIT identifier for updating an existing link instead of creating one.
- `short_code`: Optional custom slug for the new short link, such as 'summer-sale' — the branded part of the short URL (qrkit.co/summer-sale). Letters, digits, dots, hyphens, and underscores only; must be unique wit…
- `title` (string, required): Display title for the link.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `save_html_file_qr` (~264 tokens)

Host Static HTML Page

Publish a single-page static HTML site live on the web and get a permanent public URL and shareable link, plus a downloadable dynamic QR code that opens it. Use this when the user asks to create, publish, deploy, host, share, or put online a landing page, one-pager, business page, digital menu, event page, portfolio, product page, campaign page, or microsite — especially when they do not have a website or hosting provider. No separate hosting account, build step, or deployment token is required. Accepts one complete HTML document up to 6 MB: a single file, not a multi-page site. When `qr_id` is provided, update the hosted page in place while preserving its public URL and printed QR code.

Input parameters:

- `html` (string, required): Complete HTML document for a static page, such as an AI-generated landing page or microsite, to publish at a public QRCodeKIT-hosted URL and share through the returned shortlink. Maximum size is 6 MB…
- `qr_id`: Optional QRCodeKIT identifier for updating an existing hosted HTML page in place while preserving the same public URL and QR code.
- `title` (string, required): Human-readable title for the hosted page.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `host_file` (~187 tokens)

Share a File or PDF by Link

Upload and host a local PDF, image, document, spreadsheet, or other file, and get a permanent public short link plus a downloadable dynamic QR code that opens or downloads it. Use this when the user wants to publish or share an attached PDF or file — a PDF menu, brochure, catalog, CV, ticket, presentation, or any document — without a separate file-hosting account. QRCodeKIT copies the attachment to its own asset storage and validates PDFs as real PDF documents. When `qr_id` is provided, replace the hosted file while preserving the existing public URL and printed QR code.

Input parameters:

- `file` (required): Attached file to host — PDF or any other type — stored as a QRCodeKIT asset before creating the link.
- `qr_id`: Optional QRCodeKIT identifier for updating an existing link instead of creating one.
- `title` (string, required): Display title for the link.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `save_file_url_qr` (~210 tokens)

Link a Hosted File

Create or update a permanent short link and dynamic QR code for a file or PDF that is already hosted at a public URL. Use this as a fallback when the host cannot pass an attached file; prefer host_file for local or host-native attachments. When `qr_id` is provided, update the file destination while preserving the existing short link and QR code. Also used as the finalizer step by the in-chat upload form.

Input parameters:

- `asset_iri`: Optional QRCodeKIT asset IRI returned by an earlier upload.
- `file_url` (string, required): Already-hosted public file URL, preferably a QRCodeKIT asset URL.
- `original_filename`: Original filename to show for the download. Defaults to 'file'.
- `qr_id`: Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
- `title` (string, required): Display title for the QR.
- `typology` (string, required): Use 'file' for an arbitrary file or 'pdf' for a PDF.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `render_file_upload_qr_form` (~228 tokens)

Upload a File → Get a Link & QR

Open an interactive form for the user to upload a file or PDF from their device and get a permanent short link plus a downloadable dynamic QR code. Use this on Claude and other MCP hosts that cannot pass an attached file directly, whenever the user wants to share or host a PDF, menu, brochure, CV, ticket, or other file by link or QR. The form uploads the file to QRCodeKIT and saves the link; when `qr_id` is provided, it replaces the file of an existing link while preserving its short URL and QR code.

Input parameters:

- `qr_id`: Optional QRCodeKIT identifier when updating an existing QR instead of creating one.
- `title`: QR title used when the upload is saved; the form has no title input. Always pass a sensible title from the conversation; when updating an existing QR, pass that QR's current title. Defaults to the up…
- `typology` (string): Initial file typology hint for the form heading. The final typology is inferred from the uploaded file's extension, so this is only a default.

Output parameters:

- `max_bytes` (integer): Maximum accepted upload size in bytes, enforced client-side for UX.
- `qr_id`: Stable QRCodeKIT identifier when the widget updates an existing QR.
- `title`: QR title used when the upload is saved. Falls back to the uploaded filename.
- `typology` (string): Initial file typology for the form.

### `create_file_upload_session` (~131 tokens)

Create File Upload Session

Widget-only helper: mint a one-time upload session so the file upload form can send the selected file to QRCodeKIT without exposing credentials. Not intended for direct use; prefer 'Upload a File → Get a Link & QR'.

Input parameters:

- `filename` (string, required): Original filename of the selected file.
- `mime_type`: MIME type reported by the browser for the selected file.
- `size_bytes` (integer, required): Size of the selected file in bytes. Must be at most 50 MB.
- `typology` (string, required): Use 'file' for an arbitrary file or 'pdf' for a PDF.

Output parameters:

- `expires_at` (string): ISO-8601 timestamp when the session expires.
- `field_name` (string): Multipart field name for the uploaded file.
- `max_bytes` (integer): Maximum accepted upload size in bytes.
- `method` (string): HTTP method the widget must use for the upload.
- `session_id` (string): Opaque backend upload-session identifier.
- `upload_url` (string): Single-use URL the widget posts the file to (multipart form data).

### `save_whatsapp_link` (~164 tokens)

WhatsApp Chat Link

Create a short link and dynamic QR code that opens a WhatsApp conversation with a phone number in international format and an optional pre-filled message. Use this for 'chat with us' or contact buttons, customer support, reservations, sales enquiries, printed signage, business cards, or link-in-bio pages. When `qr_id` is provided, update the phone number or message while preserving the existing short link and QR code.

Input parameters:

- `message` (string): Optional pre-filled WhatsApp message.
- `phone_number` (string, required): WhatsApp phone number with international country code, such as +12025550123.
- `qr_id`: Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
- `title` (string, required): Display title for the link.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `save_email_link` (~167 tokens)

Email Action Link

Create a short link and dynamic QR code that opens a pre-filled email with a recipient, required subject, optional body, and optional CC recipients. Use this for 'contact us' flows, support or quote requests, RSVPs, feedback, reservations, or other email calls to action. When `qr_id` is provided, update the email details while preserving the existing short link and QR code.

Input parameters:

- `body` (string): Optional pre-filled email body.
- `cc`: Optional CC email addresses.
- `email_address` (string, required): Recipient email address for the email QR.
- `qr_id`: Optional QRCodeKIT identifier for updating an existing QR instead of creating one.
- `subject` (string, required): Pre-filled email subject.
- `title` (string, required): Display title for the link.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `save_app_store_link` (~210 tokens)

App Download Smart Link

Create a device-routing smart link and dynamic QR code for a mobile app: the same short link sends iPhone users to the Apple App Store and Android users to Google Play. Use this for 'download our app' campaigns in print, ads, websites, or link-in-bio pages. An app name and at least one store URL (iOS or Android) are required; an icon URL is optional. When `qr_id` is provided, update the app destinations while preserving the existing short link and QR code.

Input parameters:

- `android_url`: Optional Google Play URL, such as https://play.google.com/store/apps/details?id=com.example.
- `app_name` (string, required): App name shown on the App Store QR landing page.
- `image_url`: Optional app icon image URL.
- `ios_url`: Optional Apple App Store URL, such as https://apps.apple.com/app/example/id123.
- `qr_id`: Optional QRCodeKIT identifier for updating an existing QR instead of creating one.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `set_link_slug` (~182 tokens)

Change Link Slug

Change the custom slug (short code) of an existing QRCodeKIT short link, for any link type — e.g. turn qrkit.co/x7Ab9c into qrkit.co/summer-sale. The link keeps its identity and analytics. Use this only when the user explicitly wants to rename the short URL; to change a destination, use the corresponding save tool instead. WARNING: warn the user that the previous short URL stops redirecting and the QR image is regenerated, so any printed or shared copies of the old QR must be replaced.

Input parameters:

- `qr_id` (string, required): Stable QRCodeKIT identifier for the link.
- `short_code` (string, required): New slug for the short link, such as 'my-campaign-2026'. Letters, digits, dots, hyphens, and underscores only. Must be unique within the short-link domain.

Output parameters:

- `items` (array): QR codes visible to the active account.

### `delete_link` (~83 tokens)

Delete Link

Move an existing QRCodeKIT link and its QR code to the active account's trash. Use this only when the user asks to delete, remove, or discard a specific link. Reversible from the QRCodeKIT web app. Resolve the exact qr_id before deleting when the target is ambiguous.

Input parameters:

- `qr_id` (string, required): Stable QRCodeKIT identifier for the link.

Output parameters:

- `deleted` (boolean): Whether the QR was moved to trash.
- `qr_id` (string): Stable QRCodeKIT identifier for the QR moved to trash.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-qrcodekit-qrcodekit/mcp#diagnostics

## Score history

- 2026-09-29: 68
- 2026-09-28: 67
- 2026-09-27: 67
- 2026-09-26: 67
- 2026-09-25: 66
- 2026-09-24: 66

## Common questions

### What is the QRCodeKIT MCP server?

QRCodeKIT is an MCP server listed in the public MCP registry as com.qrcodekit/qrcodekit. Branded short links, instant page & file hosting, and dynamic QR codes with unified analytics. This page covers its hosted endpoint (https://mcp.v2.qrcodekit.com/mcp).

### Is the QRCodeKIT MCP server safe to use?

QRCodeKIT scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the QRCodeKIT MCP server expose?

QRCodeKIT exposes 14 tools: list_links, show_links, get_link_stats, save_short_link, save_html_file_qr, and 9 more. Their descriptions and schemas cost roughly 2,714 tokens of context every time the server is loaded.

### Does the QRCodeKIT MCP server require authentication?

No. We connected to QRCodeKIT without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the QRCodeKIT MCP server still maintained?

QRCodeKIT is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.v2.qrcodekit.com/mcp
- Website: https://qrcodekit.com/ai-qr-codes/mcp/
- Changelog RSS feed: https://verifymcp.io/servers/com-qrcodekit-qrcodekit/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-qrcodekit-qrcodekit/mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-qrcodekit-qrcodekit/mcp
