Truly Offline Encoding
The Reed-Solomon encoder, mask optimiser and renderer are all bundled in one small script. Load the page once, pull the Ethernet cable, and it keeps working.
Zero uploads · Zero tracking · Works offline
A complete QR studio that runs entirely inside your browser. Encode links, Wi-Fi logins, contact cards and social profiles, style every pixel, then export lossless SVG or 4K PNG. Nothing you type is ever sent to a server.
Pick a content type, fill in the fields, and watch the preview update on every keystroke. Every control below is rendered live with the HTML5 Canvas API.
Type the domain without the protocol — we add it for you and validate the result.
0 / 1800 characters
Produces a standard WIFI:T:WPA;S:…;P:…;; payload that iOS and Android join with a single tap.
Exports as vCard 3.0 — the format every mainstream phone camera imports directly into Contacts.
Generates a mailto: URI with the subject and body pre-filled in the visitor's mail app.
Leave the message empty to produce a dial-only tel: code instead of an SMS draft.
Choose a platform to load its deep-link format and matching logo stamp automatically.
Up to 4096 px for ultra-HD print. The on-screen preview always renders at your display's device pixel ratio.
Nine capabilities that normally live behind a paywall, assembled into one static page you can host anywhere for free.
The Reed-Solomon encoder, mask optimiser and renderer are all bundled in one small script. Load the page once, pull the Ethernet cable, and it keeps working.
Export a 4096 px PNG for photo-grade print workflows, or a razor-thin SVG whose file size does not change whether it lands on a sticker or a stadium banner.
Dial in exact hex colours, switch the three corner eyes between square, rounded and dot geometry, and preview a live contrast ratio so scanners never struggle.
Drop in your mark or pick a preset. The error-correction level jumps to H automatically and a clean backing plate protects the modules underneath.
Links, long-form text, Wi-Fi handshakes, vCard 3.0 contact cards, mailto drafts, SMS templates and fourteen social deep links, all validated as you type.
Arabic and Urdu flip the entire layout through CSS logical properties — not a mirrored hack — so menus, sliders and labels all read naturally right to left.
Encoding runs in well under a frame budget, so the canvas repaints as fast as you can type without blocking scroll or animation.
Semantic landmarks, labelled controls, visible focus rings, AA-or-better contrast in both themes, and full keyboard operation of the tab strip and drawer.
One click opens a clean print layout with the payload printed underneath, so production teams can verify the code before it reaches the press.
A complete walkthrough, from choosing a payload to handing files to a commercial printer.
The detailed explanatory text in this section is published in English. Headings, labels and the rest of the interface follow your selected language.
Everything starts with the tab strip at the top of the studio. A QR code is not a picture of a link; it is a container for a short string of text, and the tab you choose decides how that string is formatted so phones know what to do with it. URL is the right choice for landing pages, menus and app-store listings — pick the protocol from the dropdown and type the bare domain, because a missing https:// is the single most common reason a scan opens a search engine instead of your site. Text stores raw characters with no action attached, which is ideal for coupon codes, serial numbers and museum labels. Wi-Fi writes the handshake descriptor that lets a guest join your network without ever seeing the password. vCard builds a complete contact record for business cards and conference badges. Email and SMS pre-compose a message so the visitor only has to press send. Social loads the exact deep-link shape each platform expects, including the wa.me format WhatsApp requires for click-to-chat. Shorter payloads always win: fewer characters means a lower QR version, fatter modules and a code that scans from further away in worse light.
Scanners do not look for black and white; they look for contrast. Keep the foreground dark and the background light, and watch the live contrast readout under the colour pickers — anything below roughly 4.5:1 starts failing on cheap sensors and in dim venues. The one inversion rule you must never break is a light foreground on a dark background, because most decoders assume dark modules on a light field. The three corner eyes are the first thing a decoder locates, so treat them with care: Square is the safest and matches the specification exactly, Rounded softens the look while keeping the 1:1:3:1:1 proportion a reader expects, and Dot is the most decorative and should always be tested on at least two handsets before it goes to print. Logos are added in the stamp panel, either from the preset grid or by uploading your own PNG, SVG, JPG or WebP file. The size slider is capped at 30 percent for a reason, and 15 to 22 percent is the sweet spot where the mark stays recognisable and the code stays readable. The circular or square backing plate is not decoration — it gives the decoder a clean, predictable blank region instead of a ragged collision between your artwork and the data modules.
QR codes survive damage because every symbol carries Reed-Solomon parity data alongside your payload. Level L recovers about 7 percent of the symbol, M about 15 percent, Q about 25 percent and H about 30 percent. That redundancy costs space, so raising the level either lengthens the grid or shortens the payload you can fit. Use M for clean digital placements such as a slide deck or an email signature. Step up to Q for anything that will be handled, folded or laminated — packaging, loyalty cards, table tents. Reserve H for logo stamps, outdoor signage, vehicle wraps and any surface likely to be scratched or partially obscured. QR Forge forces level H the moment you add a logo, because the stamp is functionally identical to physical damage and the parity data is what reconstructs the modules hidden beneath it. Keep an eye on the version and module readouts beside the preview: if the grid suddenly jumps from 33×33 to 49×49, you have crossed a capacity threshold and should either trim the payload or print the code larger.
Choose the format by destination, not by habit. SVG is a mathematical description of the pattern, so it is infinitely scalable and should be your default for anything going to a professional printer, a cutting plotter or an embroidery machine. PNG is lossless raster and the universal safe bet for web pages, decks and office software; use the resolution slider to match the job, remembering that print at 300 DPI needs about 1200 pixels for a 100 mm code. 4K PNG jumps straight to 4096 pixels for large-format work. WebP produces the smallest file for web delivery and is supported by every current browser. Transparent backgrounds are available for PNG, SVG and WebP so the code can sit on a coloured panel — just make sure whatever shows through is genuinely light. Copy to clipboard drops a PNG straight into Figma, Slack or Google Docs, and Print opens a clean sheet with the decoded payload typed underneath so a production manager can proofread it before approving the run.
Three field rules prevent almost every real-world scan failure. First, respect the quiet zone: the specification asks for four empty modules of margin on all sides, which is exactly what the slider defaults to. Crop into that border and nearby text or a page edge will be read as data. Second, use the 10:1 distance ratio to pick a size — maximum reliable scan distance is roughly ten times the printed width of the symbol, so a 30 mm code on a flyer works from about 300 mm, while a code read from 10 metres across a car park needs to be a full metre wide. Never print a code below about 20 mm regardless of distance. Third, mind the substrate: glossy stock throws specular highlights that blind a camera, so prefer matte or satin finishes, and avoid placing codes on curved bottles, deep fabric folds or anywhere a shadow falls across the middle. Before any run of more than a handful of pieces, print one proof and scan it with an old low-end Android, a current iPhone, and a native camera app rather than a dedicated reader. If all three succeed from your intended distance in the actual lighting of the venue, the artwork is ready to go to press.
The detailed explanatory text in this section is published in English. Headings, labels and the rest of the interface follow your selected language.
QR Forge never stores, transmits, logs or sells the content you encode. There is no account system, no upload endpoint, no database and no server-side image renderer anywhere in this product. The Wi-Fi password you type, the phone number on your vCard and the private URL you are testing exist only as JavaScript variables inside your own browser tab, and they are destroyed the instant you close or reload that tab. Because the entire encoder ships with the page, you can verify this claim yourself: open your browser's network panel, generate as many codes as you like, and you will not see a single outbound request.
When you type, the text is converted to UTF-8 bytes, wrapped in a byte-mode segment header, padded, and passed through a Reed-Solomon encoder that computes the parity codewords. The result is interleaved, written into a module matrix, scored against all eight standard mask patterns, and the best-scoring candidate is painted to an HTML5 <canvas> element. Exports are produced locally through canvas.toBlob() for raster formats and by assembling an SVG path string in memory for vectors. Custom logo uploads are read with the FileReader API into a temporary data URL that lives in page memory and is likewise discarded on reload — your image file is never copied off your device. Nothing in this pipeline requires or contacts a network.
Because we never collect personal data, there is nothing to process under the GDPR, nothing to sell or share under the CCPA and CPRA, and nothing to knowingly collect from a child under COPPA. The only data written to your device is a small set of interface preferences — your chosen theme, your chosen language, and any site configuration saved from the administration panel — all kept in your browser's own localStorage and readable by nobody but you. Clearing your site data in browser settings removes them permanently and immediately. For the complete legal text, including how third-party advertising may behave if it is enabled on a deployment of this page, read the full Privacy Policy.
The questions our users send most often, answered with the detail a working designer actually needs.
The detailed explanatory text in this section is published in English. Headings, labels and the rest of the interface follow your selected language.
A static code holds your payload inside the pattern itself. Nothing can revoke it, no subscription can lapse, and it keeps working if this website vanishes tomorrow — but the destination is permanent, so reprint is the only way to change it. A dynamic code instead stores a short redirect address owned by a tracking provider; you gain editable destinations and scan analytics, and you accept that every scan depends on that provider staying online and that they see who scanned, when and roughly where. QR Forge deliberately generates static codes only, because that is the only way to honour the promise that nothing you type ever leaves your device.
Use the 10:1 rule: the furthest reliable scan distance is about ten times the printed width of the symbol. A 25 mm code on a business card reads from roughly 250 mm, a 100 mm poster code from about one metre, and a code meant to be scanned from ten metres across a concourse must be at least one metre across. Shrink the payload wherever you can, because a shorter string yields a lower version with physically larger modules, and bigger modules are what buys you distance. Denser codes, dim lighting, motion and older phone cameras all pull the real-world figure down, so always add margin rather than designing to the theoretical limit.
SVG for anything printed, because vectors have no resolution to run out of and the edges stay mathematically perfect at any scale. PNG for screens, slide decks and office documents, or when a printer's workflow refuses vectors — pick a pixel size of about 300 per inch of final width. 4K PNG when you need a single very large raster for banners or vehicle wraps. WebP only for web pages where every kilobyte counts. Avoid JPEG entirely: its lossy compression smears the hard black-and-white edges a decoder depends on, which is exactly why we do not offer it.
Not if you keep it modest. Reed-Solomon parity lets a decoder rebuild missing modules, and QR Forge switches to level H — around 30 percent recovery — the moment a stamp is applied. Stay at or below about 22 percent of the width, keep the backing plate enabled so the obscured region is clean rather than ragged, and never let the logo touch the three corner eyes, since those are the alignment references a reader finds first. Then test the real export on two different phones before committing to a print run.
Yes, with no limits, licence fee or attribution requirement. The QR Code symbology itself is an open ISO/IEC 18004 standard, and files you generate here are yours outright — use them on products, packaging, advertising and paid campaigns freely. The only thing you must own is the content: if you stamp a third-party logo onto a code, you still need that brand's permission to use their mark, and the preset marks in this tool are simplified geometric stand-ins intended for layout and testing rather than final trademark-accurate artwork.
The grid is not continuous — it steps through forty fixed versions, from 21×21 modules up to 177×177, and each version holds a capped number of codewords at a given error-correction level. Add one character past a threshold and the encoder must jump to the next version, which adds four modules per side and makes every module smaller at the same printed width. Raising the error-correction level does the same thing, because parity competes with your payload for the same space. Watch the version and module figures next to the preview: if they jump unexpectedly, shorten the payload, drop a level, or print the code larger.
Legal texts are published in English because that is the authoritative version. The interface around them follows your selected language.
QR Forge is a static, client-side web page. It does not ask who you are, it has no server that could receive your data, and it does not profile you. The only information that touches your device is a handful of interface preferences you set yourself. Everything below explains that position in the detail a regulator, an advertising network or a cautious enterprise reviewer would expect.
We do not collect names, email addresses, phone numbers, postal addresses, payment details, government identifiers, biometric data, precise geolocation or device fingerprints. We do not require registration and we operate no login system. Critically, we do not collect the content you encode: URLs, plain text, Wi-Fi SSIDs and passwords, vCard contact details, email drafts, SMS bodies, social handles and uploaded logo images are processed exclusively in the memory of your browser tab and are never serialised to any remote system. We have no technical ability to recover a code you generated, because no copy of it was ever created outside your device.
The generator sets no tracking cookies of its own. It does use your browser's localStorage, which is a per-origin store that never travels with network requests, to remember four things: your theme choice (dark or light), your interface language, your last-used generator options, and any site configuration saved through the administration panel. These entries are plain, human-readable JSON, they contain no identifiers, and they are visible to you at any time through your browser's developer tools. Clearing site data for this domain deletes them irreversibly. If you prefer to avoid them entirely, use a private or incognito window and the store is discarded when you close it.
The generator as shipped contains no analytics library, no tag manager, no session recorder and no heat-mapping script. An operator who self-hosts this page is free to add a privacy-respecting, cookieless analytics product, and if they do, that product's own notice governs the aggregate page-view data it gathers. In no configuration does analytics ever receive the payload of a generated QR code, because that payload exists only in page memory and is never attached to any event.
This page is built to be compatible with contextual advertising, including Google AdSense. If an operator enables such a network on their deployment, that third party may set its own cookies or similar identifiers to measure impressions, cap frequency and limit fraud. Google's use of advertising cookies enables it and its partners to serve ads based on your visits to this and other sites, and you can opt out of personalised advertising through Google's Ads Settings or via an industry portal such as the Network Advertising Initiative or Your Online Choices. Third-party vendors operate under their own privacy policies, which we neither control nor modify. We never pass the content of your QR codes to any advertising system, and we do not permit ad placements inside the generator's input or preview area.
The page loads no external fonts, no icon CDN, no JavaScript framework from a remote host and no server-side image API. Every asset — stylesheet, script, icon and favicon — is served from the same origin as the page itself. If you deploy this project to a static host such as Vercel, Netlify, Cloudflare Pages or GitHub Pages, that host will record standard web-server access logs, typically including your IP address, user agent and requested path, for security and abuse prevention. Those logs belong to the host and are covered by the host's privacy policy, not ours.
Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection. Under the CCPA and CPRA you have rights to know, delete, correct and opt out of sale or sharing. We honour all of them by design rather than by process: since we hold no personal data about you, there is no record to disclose, correct, export or delete, and no sale or sharing of personal information takes place. You can exercise the only data right that is technically meaningful here — erasure of locally stored preferences — yourself, instantly, by clearing this site's data in your browser settings. If you still wish to submit a formal request or ask a question, use the contact form and we will respond within five business days.
This tool is a general-audience utility and is not directed at children under 13. Consistent with COPPA, we do not knowingly collect personal information from children; indeed, we do not knowingly collect personal information from anyone. Should a parent or guardian believe a child has somehow transmitted personal data to us, please get in touch and we will investigate, although in practice no mechanism exists through which such a transmission could occur.
Keeping data on your device is the strongest security guarantee we can offer: there is no central store to breach, no credential database to leak and no backup tape to lose. We recommend serving the page over HTTPS, which every supported static host provides by default, so that the script itself cannot be tampered with in transit. You remain responsible for the physical and account security of the device on which you generate codes, and for how you distribute the files you export.
If this policy changes we will update the date at the top of the page and, for material changes, add a visible notice on the homepage. Continuing to use the tool after an update constitutes acceptance of the revised policy. Questions, concerns and formal data requests can be sent through the contact page or directly by email to the address published there.
Legal texts are published in English because that is the authoritative version. The interface around them follows your selected language.
By loading or using QR Forge you agree to the terms set out on this page. If you do not accept them, please close the page and do not use the generator. These terms apply to the hosted page, to the source files if you self-host them, and to every QR code you produce with either.
You may use QR Forge for any lawful purpose, personal or commercial, free of charge and without attribution. You may generate unlimited codes, use them in paid advertising, print them on products you sell, embed them in client deliverables, and bill your clients for work that includes them. You may also download, modify, self-host and redistribute the source files, including inside a commercial product of your own.
You agree not to use the tool to encode destinations or content that is unlawful, fraudulent, deceptive or harmful. Prohibited uses include, without limitation: phishing pages and credential-harvesting forms; malware, drive-by downloads and exploit kits; payment redirection scams and the practice known as quishing, where a legitimate code on a poster, parking meter or invoice is covered with a malicious sticker; harassment, doxxing, or the distribution of non-consensual intimate imagery; child sexual abuse material; and any attempt to impersonate a person, brand or public authority. You also agree not to deliberately overload, deface or misrepresent the tool itself.
The QR Code symbology is defined by the open ISO/IEC 18004 standard, and the codes you generate are not encumbered by any licence from us. You own the output files and the content you encode. The QR Forge name, interface design, written guides and source code remain the property of their authors; the source is provided for your use and modification under the licence accompanying the distribution you obtained. Third-party trademarks referenced by the social and brand presets belong to their respective owners, are used here only to identify the corresponding platform or link format, and imply no endorsement, affiliation or sponsorship. The preset marks are simplified geometric stand-ins for layout and testing — obtain official brand assets and permission before publishing anything that represents another company's identity.
QR Forge is provided "as is" and "as available", without warranties of any kind, whether express, implied or statutory, including any implied warranties of merchantability, fitness for a particular purpose, accuracy, or non-infringement. We do not warrant that the tool will be uninterrupted, error-free, or compatible with every browser, scanner application, camera sensor, printing process or substrate. Scan reliability depends on factors outside our control, including your chosen colours, size, error-correction level, logo coverage, print quality, surface finish, ambient lighting and the decoding software on the reader's device. You are solely responsible for testing every exported code on real devices before reproducing it at scale.
To the maximum extent permitted by applicable law, neither the authors nor any contributor or operator of QR Forge shall be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, nor for any loss of profit, revenue, data, goodwill or business opportunity, arising out of or in connection with your use of the tool — including, specifically, the cost of reprinting materials that carry a code which fails to scan, revenue lost while such materials are out of service, or any consequence of an incorrect payload being encoded. Because the tool is supplied free of charge, our aggregate liability to you for all claims is limited to zero. Some jurisdictions do not allow the exclusion of certain warranties or limitation of incidental damages, so parts of this clause may not apply to you; in that case our liability is limited to the smallest amount permitted by law.
You agree to indemnify and hold harmless the authors and operators of QR Forge from any claim, demand, loss or expense, including reasonable legal fees, arising from content you encode or from your breach of these terms. We may revise these terms at any time by publishing an updated version on this page with a new date; material changes will additionally be announced on the homepage, and continued use after publication constitutes acceptance. If any provision is held unenforceable, the remainder stays in force. These terms are governed by the laws of the jurisdiction in which the operator of your deployment is established, without regard to conflict-of-law rules.
The detailed explanatory text in this section is published in English. Headings, labels and the rest of the interface follow your selected language.
We started QR Forge after one too many frustrating afternoons. A designer on our team needed a single Wi-Fi code for a café client. The first site wanted an email address before it would show a download. The second watermarked the output. The third silently turned the code into a tracked redirect through a domain nobody had heard of, meaning the café's guests would be logged by a stranger and the code would die the moment that company's billing lapsed. The fourth produced a 300-pixel JPEG. Not one of them simply encoded the string and handed back a clean vector file. That is a solved problem — it has been solved since 1994 — and it should not cost a signup, a subscription or your customers' privacy.
Build the QR tool we wanted: instant, free, private by architecture rather than by promise, and genuinely good enough for professional print work. Everything a commercial generator charges for — 4K raster output, lossless vector export, logo stamping, colour control, contact cards, Wi-Fi handshakes — runs here in a few kilobytes of vanilla JavaScript with no account and no network call. If a feature cannot be built without sending your data somewhere, we would rather not ship that feature at all. Static codes only, no tracking redirects, no exceptions.
QR Forge is deliberately boring technology: three files, no build step, no framework, no package manager, no CDN. That is a design position, not laziness. A page with no dependencies cannot be broken by someone else's breaking change, cannot leak through a compromised third-party script, and will still open in a browser a decade from now. It loads fast on a weak connection, works on a mid-range Android from 2017, respects reduced-motion and high-contrast preferences, and is fully operable by keyboard and screen reader. We also treat localisation as infrastructure rather than decoration, which is why Arabic and Urdu get a properly mirrored layout built on CSS logical properties instead of a flipped stylesheet.
We are a small, distributed group of front-end engineers, a typographer and an accessibility consultant who met through open-source work and keep this project running in the margins of our day jobs. Nobody draws a salary from it. It is funded, if at all, by unobtrusive contextual advertising placed outside the tool itself — never inside the input fields or over the preview — and it will stay free whether that covers the domain or not. If you have found a bug, a mistranslation, a scanner that disagrees with our output, or an accessibility gap, the contact page reaches a human who actually reads it.
The detailed explanatory text in this section is published in English. Headings, labels and the rest of the interface follow your selected language.
We read every message that arrives, and a person — not an autoresponder — writes back. The fastest way to get a useful answer is to tell us what you were trying to encode, which browser and operating system you were using, and what happened instead of what you expected. If a generated code refuses to scan, mentioning the phone model and the scanning app helps enormously, because decoder tolerances differ more than most people realise. Screenshots are welcome; so is the exported SVG, which lets us reproduce the exact symbol you are holding.
Bug reports and scanner compatibility problems are our highest priority. We also welcome translation corrections — our eight locales cover the whole interface, but they have not been through professional review, so if a label reads awkwardly in your language we would genuinely rather be told. Feature requests are read and kept on a public-facing list, though we weigh every one against the no-network rule, so anything requiring a server or an account will be politely declined. Accessibility feedback jumps the queue: if a control is unreachable by keyboard, mislabelled for a screen reader, or fails a contrast check in either theme, we treat that as a defect rather than an enhancement. Press, partnership and licensing enquiries are fine here too.
We aim to reply within two business days and commit to a maximum of five; formal data-protection requests are answered inside the statutory window. This form has no backend — submitting it validates your input locally and then opens a pre-filled draft in your own mail client, so your message travels directly from you to us with nothing stored on this site in between. If you would rather skip the form entirely, email hello@qrforge.app directly.
Converted to a Base64 data URL and injected into <link rel="icon"> the moment it is selected.
Writes straight into the :root custom properties, so every button, badge and gradient heading updates instantly.
Leave a field empty to fall back to the translated default for the active language.
Changes apply live and are written to localStorage automatically. Every visitor to this browser profile sees them on next load.