Editable QR Codes Without a Subscription: One Line of Config
The answer to "but I need to change the destination later" is not a subscription. It is a redirect path on a domain you already own.
yourcompany.com/m — and configure that path to redirect wherever you want. On nginx that is one return 302 line. You keep editable destinations and per-placement analytics, while the printed code depends on nothing but a domain you already pay for.The dynamic-QR pitch bundles two things that need not be bundled: a redirect, which is genuinely useful, and someone else owning it, which is the entire problem. Unbundle them and the redirect stays while the landlord goes.
Why does this work?
Your printed code contains yourcompany.com/m as literal bytes, so nobody can revoke it, meter it, or log it — and what /m serves is configuration you change whenever you like. It is the same mechanism providers sell; they simply charge rent on a domain that is not yours. Static vs dynamic covers the underlying distinction.
What do you get compared with each alternative?
| Dynamic (rented) | Static, direct URL | Static + your own redirect | |
|---|---|---|---|
| Can be switched off by a third party | Yes | No | No |
| Recurring cost | Monthly, often per code | None | None beyond your existing domain |
| Change the destination after printing | Yes | No | Yes |
| Who logs the scan | The provider | You | You |
| What the scanner's preview shows | An unfamiliar short domain | Your domain | Your domain |
| Survives the vendor going out of business | No | N/A | Yes |
| Setup effort | Sign up | None | One config line |
The right-hand column is what the industry sells, minus the counterparty risk. It is not a compromise — it is strictly better on every row that matters.
How do you design the URLs?
Keep them short, because shorter payloads produce lower-density patterns that scan more reliably from a distance and survive worse printing.
- Use a brief path:
/mfor menu,/p1for poster one,/wfor Wi-Fi info. - Give each physical placement its own path. That is what buys you per-placement analytics later, and the ability to repoint one placement without touching the others.
- Prefer paths over query strings for the printed part, then add campaign parameters in the redirect target.
yourcompany.com/p1can forward toyourcompany.com/promo?src=poster-lobby&utm_medium=qr. - Use HTTPS and skip
www.if your site works without it — every character removed simplifies the pattern. - Never reuse a path for a different campaign later. Old printed copies will still be out there pointing at it.
A short path also means the code can be printed smaller, or larger with the same module size, which is a practical durability gain on table tents and outdoor signage.
How do you set up the redirect?
Use a 302 while a campaign is live and you may want to repoint it. Use a 301 only when the destination is genuinely permanent, since browsers and scanners cache 301s aggressively and you may not be able to take it back.
nginx
Inside your server block: location = /m { return 302 https://yourcompany.com/menu?src=table; } — then nginx -t and reload. One line per placement.
Cloudflare
Use a Bulk Redirect list, or a Single Redirect rule for a handful of paths. No origin change is needed, which makes this the fastest option if your DNS is already there.
Netlify or Vercel
Add a _redirects file containing /m /menu?src=table 302, or the equivalent redirects entry in vercel.json. Deploy to change a destination.
Next.js
Add to next.config.js a redirects() entry returning { source: '/m', destination: '/menu?src=table', permanent: false }. Ships with your next deploy.
Apache
In .htaccess: Redirect 302 /m https://yourcompany.com/menu?src=table.
How do you plan paths for a multi-year print programme?
Printed codes outlive the campaigns that created them, so the path scheme needs to survive people leaving and sites being rebuilt. A few conventions make that cheap.
Namespace by placement rather than by campaign. /p/lobby-01 stays meaningful when the promotion changes; /spring-sale becomes a lie the following year while the sign is still on the wall. Keep a register — a single file in the repository, or a spreadsheet next to the print artwork — listing every path, where it currently points, what it was printed on, how many copies exist, and when that material is due for replacement. Without that register, the redirect config becomes a set of lines nobody dares delete.
Never delete a path while printed copies exist. Retire it instead: point it at a sensible landing page rather than removing the rule, so an old code degrades to something useful rather than a 404. And keep the rules in version control beside the site, so a hosting migration carries them along instead of losing them — the most common way this approach fails in practice is a redeploy that quietly drops the redirect file.
Does printing a longer URL make the code harder to scan?
Slightly, and it is worth understanding because it is the one genuine technical argument the shortener industry has.
A QR code's payload determines its version — the grid size — and longer payloads need more modules. More modules at a fixed physical size means smaller modules, which are harder for a camera to resolve from a distance or through poor print quality. A provider's six-character short link genuinely produces a lower-density pattern than a long URL with campaign parameters attached.
The answer is not to rent their domain, though — it is to keep your own path short and move the parameters into the redirect target. yourcompany.com/p1 is around 22 characters, comfortably inside the low versions of the ISO/IEC 18004 specification, and the ?utm_medium=qr&src=poster-lobby part never appears in the printed pattern at all because the redirect adds it. You get a sparse, robust code and full attribution, which is exactly the combination the short link was supposed to be necessary for.
How do you get analytics without a third party?
You already have them. Every scan is a request to your own server, so your access logs record it, and your analytics counts the landing page hit.
Give each placement a distinct src parameter in the redirect target and you get exactly the per-poster breakdown the dashboard was selling: which lobby sign performs, which table tents get used, whether the takeaway sticker is worth printing. The difference is that the data is yours, the diner contacted only you, and the code keeps working regardless of anyone's billing status. What a QR proxy logs covers what you avoid handing over.
What is the failure mode of this approach?
Honesty requires naming it: you now depend on your own domain. If you let it lapse, or migrate hosting and forget the redirect paths, the printed codes break.
That is a real risk, and it is a fundamentally different kind from the one it replaces. It is a dependency you control, can renew for years in advance, and can hand to a successor. Nobody can price you out of it, meter it, or decide to monetise your customers through it. Three practical mitigations: register the domain well beyond the life of the printed material, keep the redirect paths in version control next to the site, and document them wherever your print artwork lives.
If you do not need editability at all — and for a menu, a Wi-Fi code, or a contact card you usually do not — skip the redirect and encode the destination directly. Fewer moving parts, same permanence.
Frequently asked questions
- Can a static QR code point to a redirect?
- Yes, and that is the whole technique. The code is static because its payload never changes; what that URL serves is entirely up to you. You keep permanence in the printed artefact and flexibility in your own configuration.
- Do I need a special short domain?
- No. A short path on your existing domain is enough, and it is better than a separate short domain because the scanner's preview shows a name your customers recognise. A dedicated short domain is a nice-to-have, not a requirement.
- Should I use a 301 or a 302 redirect?
- A 302 while you may still want to change the destination — 301s are cached hard by browsers and can be difficult to reverse. Switch to 301 only once a destination is genuinely permanent.
- What if I do not have a website at all?
- Then skip the redirect layer entirely and encode the destination directly — a static code pointing at your existing booking page, social profile, or map listing works and costs nothing. If you want the option to move later without reprinting, the minimum viable version is a domain plus a redirect service, which is far cheaper than per-code QR pricing and leaves the domain in your name.
- What if I move my website to a new domain later?
- Keep the old domain registered and keep the redirect paths serving. Printed codes are permanent artefacts, so the domain in them should be treated as a long-term commitment — which is exactly why it should be one you own.
Generate the static code for your redirect path: URL QR code. If a rented code is already in trouble, start with the hostage recovery guide, or read the truth about QR code scams for the full picture.
Ready for a static QR code?
Generate one in your browser — no account, no tracking, no subscription. What you create belongs to you.
Related reading
Static vs Dynamic QR Codes: What Every User Should Know
One encodes your content; the other encodes a redirect. That single difference determines whether your QR code will still work in five years.
QR Code Held Hostage: Buy One Month, Never the Annual Plan
Triage for a code that has been switched off: who actually controls it, what escape costs, and the one move that stops it recurring.
Restaurant QR Menus: Editing the Menu Isn't Editing the Code
You are told you need an editable code. What actually changes daily is the content of the menu page, not its address — and a static code handles that for free.
Licence-Free Since 2000: So What Is a Paid QR Code For?
The monthly number is not the price. The price is that number multiplied by every code you printed and every month the material stays in the world.
The Truth About QR Code Scams: How 'Free' Generators Extort Users
Dynamic QR codes let providers track, edit, disable, and monetize your codes after you've printed them. Here's how the scheme works and how to avoid it.