QR Tiger

A library call with a UI

YES · focused build
price $7/mo per seatsubscription / year $84estimated build time one sittingreplaced by 0 people

A library call with a UI. Peak "why is this a subscription."

Build verification: not recorded. How we judge buildability

What you give up

  • hosted dynamic-QR redirects on their domain
  • their scan-analytics dashboard
  • bulk generation UI

Your build guide

The stack, security requirements, and agent rules for a focused replacement.

Before you start

  • Node, SQLite on persistent disk, a stable public HTTPS origin and authenticated owner access. The domain must remain under the owner’s control for printed dynamic codes to keep working.
  • Implementation components: Node.js, TypeScript and Express with server-rendered HTML and small browser modules. SQLite through better-sqlite3 with migrations, prepared statements and a single background worker. qr-code-styling for QR rendering, with an explicit public HTTPS origin and non-recycled redirect slugs.
  • Scope boundary: Tracking depends on maintaining the domain and hosting; no lifetime availability claim.
01
Node.js, TypeScript and Express with server-rendered HTML and small browser modules.
02
SQLite through better-sqlite3 with migrations, prepared statements and a single background worker.
03
qr-code-styling for QR rendering, with an explicit public HTTPS origin and non-recycled redirect slugs.
04
Domain model: QR designs, stable redirect slugs, destinations, revision history and export dimensions
engineering roadmap

Implementation plan

1

Phase 1

Scope and fixtures. Implement this bounded workflow: Generate QR codes that point to stable user-owned short URLs, preview contrast/quiet zone and export SVG or PNG. Let the owner edit the destination without changing the printed code. Record prerequisites, select representative user-owned fixtures and document the unsupported features: Tracking depends on maintaining the domain and hosting; no lifetime availability claim.

2

Phase 2

Durable model. Model QR designs, stable redirect slugs, destinations, revision history and export dimensions Add migrations or a versioned document format, explicit validation, stable IDs and a visible import-error report. Preserve this rule: Scan reliability cannot be guaranteed from appearance alone; slugs are unique and destination edits accept only approved HTTP/HTTPS URLs.

3

Phase 3

Complete the first useful path. Implement the workflow's input, review and output interface, with clear controls and explicit empty/error states. Use short SQLite transactions and persist job state before starting work. Give retries stable operation IDs; report incomplete or unknown results instead of silently repeating them.

4

Phase 4

Permissions and integration failure. Public routes accept only their documented inputs with rate/size limits. Protect every owner/customer action with authenticated authorization and CSRF checks; keep secrets outside exports and redact personal data from logs. Request integration credentials and permissions only for the enabled feature; show a disconnected state instead of mock results.

5

Phase 5

Portable handoff. Use a consistent SQLite backup and an attachment manifest. Export portable JSON/CSV, then restore to a new directory without overwriting the original data. Include setup, operating limits, fixture walkthrough and shutdown/restart instructions in the README.

6

Phase 6

Acceptance scenarios. Print or scan a fixture at the intended size, change its destination and keep the code valid; deleting a slug shows a deliberate inactive page rather than reassigning it. Repeat the workflow after restart and with a denied permission or unavailable dependency; show recoverable failure rather than a success placeholder.

the pro prompt
download AGENTS.md
WORKING SLICE
Generate QR codes that point to stable user-owned short URLs, preview contrast/quiet zone and export SVG or PNG. Let the owner edit the destination without changing the printed code.

Build this scoped QR Tiger-inspired workflow with a documented data model and visible failure states.

Architecture
- Node.js, TypeScript and Express with server-rendered HTML and small browser modules.
- SQLite through better-sqlite3 with migrations, prepared statements and a single background worker.
- qr-code-styling for QR rendering, with an explicit public HTTPS origin and non-recycled redirect slugs.

Prerequisites and limits
Node, SQLite on persistent disk, a stable public HTTPS origin and authenticated owner access. The domain must remain under the owner’s control for printed dynamic codes to keep working.
Outside this release: Tracking depends on maintaining the domain and hosting; no lifetime availability claim.

Data model and correctness
QR designs, stable redirect slugs, destinations, revision history and export dimensions
Invariant: Scan reliability cannot be guaranteed from appearance alone; slugs are unique and destination edits accept only approved HTTP/HTTPS URLs.
Use short SQLite transactions and persist job state before starting work. Give retries stable operation IDs; report incomplete or unknown results instead of silently repeating them.

Security and privacy
Public routes accept only their documented inputs with rate/size limits. Protect every owner/customer action with authenticated authorization and CSRF checks; keep secrets outside exports and redact personal data from logs.

Recovery and export
Use a consistent SQLite backup and an attachment manifest. Export portable JSON/CSV, then restore to a new directory without overwriting the original data.

Implementation order
1. Phase 1 — Scope and fixtures. Implement this bounded workflow: Generate QR codes that point to stable user-owned short URLs, preview contrast/quiet zone and export SVG or PNG. Let the owner edit the destination without changing the printed code. Record prerequisites, select representative user-owned fixtures and document the unsupported features: Tracking depends on maintaining the domain and hosting; no lifetime availability claim.
2. Phase 2 — Durable model. Model QR designs, stable redirect slugs, destinations, revision history and export dimensions Add migrations or a versioned document format, explicit validation, stable IDs and a visible import-error report. Preserve this rule: Scan reliability cannot be guaranteed from appearance alone; slugs are unique and destination edits accept only approved HTTP/HTTPS URLs.
3. Phase 3 — Complete the first useful path. Implement the workflow's input, review and output interface, with clear controls and explicit empty/error states. Use short SQLite transactions and persist job state before starting work. Give retries stable operation IDs; report incomplete or unknown results instead of silently repeating them.
4. Phase 4 — Permissions and integration failure. Public routes accept only their documented inputs with rate/size limits. Protect every owner/customer action with authenticated authorization and CSRF checks; keep secrets outside exports and redact personal data from logs. Request integration credentials and permissions only for the enabled feature; show a disconnected state instead of mock results.
5. Phase 5 — Portable handoff. Use a consistent SQLite backup and an attachment manifest. Export portable JSON/CSV, then restore to a new directory without overwriting the original data. Include setup, operating limits, fixture walkthrough and shutdown/restart instructions in the README.
6. Phase 6 — Acceptance scenarios. Print or scan a fixture at the intended size, change its destination and keep the code valid; deleting a slug shows a deliberate inactive page rather than reassigning it. Repeat the workflow after restart and with a denied permission or unavailable dependency; show recoverable failure rather than a success placeholder.

Acceptance
Print or scan a fixture at the intended size, change its destination and keep the code valid; deleting a slug shows a deliberate inactive page rather than reassigning it.
Use real source data or clearly labeled fixtures. Explain unsupported input and provider failures; do not fabricate analytics, delivery receipts, accuracy claims or security guarantees.

Optional agent guidance
Optional external skill: [web-design-guidelines](https://github.com/vercel-labs/agent-skills/blob/main/skills/web-design-guidelines/SKILL.md) — Review web interfaces for accessibility, keyboard focus, forms, navigation and interaction quality. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Optional external skill: [sharp-edges](https://github.com/trailofbits/skills/blob/main/plugins/sharp-edges/skills/sharp-edges/SKILL.md) — Review security-sensitive APIs and configuration for dangerous defaults and easy-to-misuse interfaces. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Project rule — data model: QR designs, stable redirect slugs, destinations, revision history and export dimensions
Project rule — preserve this invariant: Scan reliability cannot be guaranteed from appearance alone; slugs are unique and destination edits accept only approved HTTP/HTTPS URLs.
Project rule — acceptance evidence: Print or scan a fixture at the intended size, change its destination and keep the code valid; deleting a slug shows a deliberate inactive page rather than reassigning it.

$ open in your agent (prompt prefilled, you press enter), copy the prompt or copy or download AGENTS.md

share on X ↗

Alternatives to building your own

MMini QRA tidy QR workshop that generates, scans and batches without asking for a credit card or your life story.2.3kaug 2026open source↗QR TIGER FreeThe same generator gives away unlimited static codes that never expire; dynamic codes stop at three and 500 scans each.$0free↗QRCode MonkeyStatic QR codes, unlimited scans and useful exports; tracking is the bit they keep for paying customers.$0free↗

all 3 free alternatives to QR Tiger →· no votes, no pay-to-list · just what's real

QR Tiger pricing

planmonthlyannual (per mo)what you get
free$0/user$0/userUnlimited static QR codes; 3 dynamic QR codes; 500 scans per dynamic code.
regular$7/user$5.42/user12 dynamic QR codes; 5 MB file upload; 500 API requests/month; 1 user.Annual total is $65.
advanced—$16/user200 dynamic QR codes; 10 MB file upload; 3,000 API requests/month.Annual-only.
premium—$37/user600 dynamic QR codes; 20 MB file upload; 10,000 API requests/month; 1 white-label domain.Annual-only.
professional—$89/workspace1,200 dynamic QR codes; 60 MB file upload; 1 additional user.Annual-only.
enterprise——Custom dynamic-code, API, user and domain limits.Contact sales.

free tierunlimited static QR codes; 3 dynamic QR codes; 500 scans per dynamic code

billingRegular offers monthly + annual; Advanced, Premium and Professional are annual-only; Enterprise quote-based

hidden costsdynamic codes and advanced analytics depend on an active subscription; upgrades and refunds can be prorated; higher API, user and white-label needs require a higher plan

pricing sources checked 2026-08-13 · pricing source ↗

Questions about QR Tiger

Can you build your own QR Tiger with AI?

The verdict is yes for the scoped workflow. A library call with a UI. Peak "why is this a subscription."

What does the QR Tiger build prompt cover?

The prompt starts with this scope: Generate QR codes that point to stable user-owned short URLs, preview contrast/quiet zone and export SVG or PNG. Let the owner edit the destination without changing the printed code. Full-product capabilities excluded from the comparison include: hosted dynamic-QR redirects on their domain; their scan-analytics dashboard; bulk generation UI. Follow the implementation plan and its prerequisites before expanding the build.

How do I use the prompt, AGENTS.md and agent skills?

Start with the QR Tiger prerequisites and stack, then copy the prompt into your coding agent. Save the project rules as AGENTS.md in the project root. Linked skills are optional packages or source instructions for specific tasks; review their current contents and install only those matching the chosen stack. A skill does not supply API credentials or verify the finished app.

How long will this QR Tiger project take?

The catalogue estimate is one sitting for the limited scope. Setup, integration approvals, debugging, deployment and ongoing maintenance can add time. This is an estimate, not a delivery guarantee.

What would I give up by replacing QR Tiger?

hosted dynamic-QR redirects on their domain; their scan-analytics dashboard; bulk generation UI. Compare these limits with the workflow you actually need.

What price is this guide comparing against?

The recorded Regular plan is $7/mo per seat (monthly per user), checked 2026-08-13. Check the linked pricing source before buying. Building your own also has hosting, API and maintenance costs; the recorded amount is not a guaranteed saving.

What can I use instead of building QR Tiger?

Mini QR: A tidy QR workshop that generates, scans and batches without asking for a credit card or your life story. QR TIGER Free: The same generator gives away unlimited static codes that never expire; dynamic codes stop at three and 500 scans each. QRCode Monkey: Static QR codes, unlimited scans and useful exports; tracking is the bit they keep for paying customers. Compare all listed options at https://howtovibecodeit.dev/qr/alternatives. Check each option's license, hosting needs and feature limits.

Every week, more subscriptions die.

New verdicts, new prompts, the week's most-doomed apps.
One email. Unsubscribe in one click.

last week:100 Questions · KINDA1of10 · KINDA1Password · KINDA+1090 more

free forever · no scanner spam · the prompt stays on the site, the deaths come to you

$weekly: what got a verdict, what died.