Dynamic QR codes: the complete guide
What makes a QR code dynamic, what that indirection buys and costs, what scan tracking can honestly tell you, and how to choose a provider.
- qr-codes
- marketing
Every QR code you have ever scanned belongs to one of two families. In one, the picture is the message: the destination is baked into the dots, and the code will do the same thing forever. In the other, the picture is a pointer: the dots hold a short permanent link, and where that link goes can be changed after the poster is printed, the menu laminated, the van wrapped.
The industry calls these static and dynamic. This guide is about the second family: what the indirection actually buys you, what it honestly costs, when the boring static code is the better choice, and how to pick a provider you will not regret in a year.
A disclosure up front: we make Tessera, a QR code tool, so we sell one of the things this guide describes. Where that colours a recommendation, we say so in the sentence itself.
Where the message lives
The whole difference between static and dynamic is one question: is the destination in the dots, or behind them?
A QR code is a short piece of text written for cameras; that is all it has ever been since its invention in 1994 for tracking car parts. A static code writes your destination into the picture itself. A dynamic code writes a short link into the picture instead, and the provider holding that link forwards each scan to wherever you have currently pointed it. The phone does not know or care which kind it is reading.
The mechanics have a whole article of their own: what a QR code is actually doing. It covers what the dots mean, why damaged codes still scan, and why contrast decides everything, so this guide will not repeat any of that. Everything from here is about the decision between the two families and what living with a dynamic code is like.
One note on names. In our own tool we call the two kinds fixed and editable rather than static and dynamic, because that is what they mean to the person choosing. This guide uses the industry words since they are the ones you will meet everywhere else.
What a dynamic code buys you
Three things, and it is worth being precise, because everything a dynamic code costs is paid for one of these.
The destination can change after printing. This is the headline. The menu moves to a new page, the promotion ends, the form gets replaced, the domain migrates, and every printed copy follows along, because the paper only ever knew the permanent link. For anything printed in quantity, or expensive to reprint, or embedded somewhere unreachable, this is the difference between an edit and a landfill.
There is an off switch. A code that escapes into the world, an old campaign that keeps getting scanned, a poster you no longer control: a dynamic code can be revoked. After that, a scan gets an honest “this code has been switched off” rather than whatever your old destination has since become. A static code has no off switch. Whatever it points at, it points at for the lifetime of the paper.
Scans can be counted. Because every scan passes through the permanent link, the provider can count them. That is the entire basis of QR analytics, and we will be precise about what it can and cannot tell you below.
What it costs, stated plainly
The vendors selling dynamic codes, ourselves included, are quieter about this part, so here it is in full.
You are now depending on someone. The permanent link lives on the provider's domain and has to answer correctly for as long as your printed material exists. If the provider shuts down, gets acquired, or deletes your account, every code they hold for you dies with them. A static code cannot have this problem: it needs nobody's permission to keep working, including ours.
Watch for free codes that expire. A common industry pattern: create a dynamic code on a free trial, print it, and discover weeks later that the code now redirects to an upgrade page because the trial lapsed. The material in circulation is then advertising the provider, not you. Before printing anything through any provider, find the sentence in their terms that says what happens to existing codes when you stop paying. If you cannot find it, that is your answer. We went and read what four providers actually say, and what happens when a code expires is less uniform than the pricing pages suggest.
Every scan is a round trip. A static code takes the phone straight to your destination. A dynamic one goes through the provider first. In practice this adds a fraction of a second and requires the provider to be up; it is rarely a real problem, but it is not nothing, and offline destinations like WiFi credentials cannot work this way at all.
When a static code is the better choice
An honest guide to dynamic codes has to include this section. The test is simple: if the destination will never change and you do not need to count anything, static wins. It is free, it is permanent, and it cannot be broken by anyone's business model, including the provider's.
Good static cases: a link on a business card to a page you have owned for years, a WiFi code for guests, a plaque, a wedding invitation, anything personal or sentimental that should outlive every subscription you currently hold.
Good dynamic cases: menus, posters and flyers for anything that recurs, product packaging, print advertising you are paying to place, signage that is expensive to produce, and any campaign where you genuinely intend to look at the scan numbers and decide something.
We keep a fuller side by side comparison in mind for its own article; the short version is that the choice is about time. Static codes are for destinations measured in years. Dynamic codes are for destinations measured in campaigns.
What people actually put in QR codes
The payload is just text, so a code can carry more than a web address: plain text, a phone number or SMS, WiFi credentials, a contact card, a place on a map, a calendar event. Our free generator covers all of those without an account, and so do plenty of others.
The distinction that matters for this guide: only destinations you host can usefully be dynamic. A URL can sit behind a permanent link and be changed later. WiFi credentials, contact cards and calendar events are handed directly to the phone at scan time, so there is nothing to redirect; they are static by nature. If someone offers you an “editable WiFi code”, read the small print carefully, because the usual trick is routing the scanner to a web page first, which is a worse experience than the native one.
So the practical rule: URLs are where the dynamic decision applies. Everything else, make static, make correct, and test before printing.
Scan tracking, honestly
A scan of a dynamic code is a web request to the permanent link, and a web request carries a little metadata: when it happened, and a user agent string that reveals the broad kind of device. From that, a provider can honestly give you scan counts over time, a rough split of device types, and an estimate of how many scanners were distinct. Ours also lets you export the raw counts, because your data being portable is one of the provider questions below.
What scan tracking cannot honestly tell you: who scanned, whether they read what they found, whether they bought anything, or reliably where they were beyond what a network address hints at. A QR provider sees one instant of the journey. If you need conversion numbers, put your usual web analytics on the destination page, and use a distinct destination per campaign so the source shows up there.
Two habits make the numbers you do get worth having. Compare like with like: a poster in a station and a code on a receipt have no business being judged against each other. And decide before printing what number would change your mind about anything; a metric nobody will act on is decoration.
The trust problem
QR codes have a security reputation to manage, and it is partly deserved. Because a human cannot read the dots, a code is a link whose text is invisible, and criminals exploit that by pasting their own stickers over legitimate codes or mailing codes that lead to fake payment pages. The FTC's consumer alert on the subject is short and worth reading.
You cannot fix criminals, but you can avoid looking like them. Give the scanner reasons to trust the moment of scanning. A destination on a domain that matches who you claim to be. A landing page that says where the reader has arrived. No surprise requests for payment details from a code on a lamp post. Modern phones show the link's domain before opening it; assume your most valuable scanner reads that line, and make sure what it says would reassure them.
This cuts one way in the static versus dynamic decision: a dynamic code shows the provider's domain at scan time, not yours. A provider whose domain is short, stable and unembarrassing is doing part of your reassurance for you.
Print still decides whether it scans
Everything in this guide happens after the phone reads the code, and none of it matters if the phone cannot. The full detail is in the mechanics article, and the specific case of a code that worked on screen and fails on paper has its own. The four rules that catch nearly every failure in the wild:
- Keep what the code carries short, so the grid stays coarse and scans from a distance.
- Keep the contrast high, dark marks on a light ground.
- Leave the pale border alone; it is part of the code.
- Print at least two centimetres across, bigger if people scan from further away.
And then the rule that outranks the other four: scan the real, printed thing with a real phone before you produce a thousand of it. Not the on screen preview. The print.
One code or several
Because dynamic codes are cheap to make and can be counted separately, a campaign does not have to share one. Give the station poster, the counter card and the receipt each their own code pointing at the same destination. The scan counts then become a comparison of placements: you learn where your scanners actually are, for the price of making three codes instead of one.
This is the most useful thing QR analytics does, and it needs no cleverness at all, just separate codes per placement, named so you can tell them apart in a year.
Choosing a provider
The questions that matter, in the order they will matter to you:
- What happens to existing codes if you stop paying? The only question with landfill attached. Get the answer in writing before printing.
- Can you export your data? Scan history and the list of codes. If it cannot leave, it is not yours.
- What domain do scanners see? Short, stable, professional. Your scanners will be shown it at every scan.
- Does the free tier expire codes? See the trap above. “Free forever” and “free trial” are different products wearing the same button.
- Is there an honest off switch? Revoking a code should give scanners a clear “gone”, not a redirect to somewhere weird.
Since we are a vendor, our own answers, briefly. Tessera's static codes are free, need no account, and never depend on us at all. Editable codes keep working on their permanent link, can be revoked to an explicit “switched off” answer, and their scan counts export. We would rather you print a static code that never needs us than a dynamic one you did not need.
A checklist before you print
- Static or dynamic decided deliberately, using the time test above.
- The destination is live, correct, and on a domain a stranger would trust.
- You know, in writing, what happens to the code if you stop paying.
- Contrast high, border intact, size two centimetres or more.
- The real print scanned with a real phone, ideally more than one.
- If you will compare placements, each placement has its own code.
- The expired or revoked behaviour is something you would be happy for a scanner to see.
Where to go next
If you want to understand what the dots are actually doing, and why a code that half scans still works, read what a QR code is actually doing. If you want to make one now, Tessera generates static codes free without an account, and editable ones when the destination might change.
And if the same campaign also sends email, we keep a complete guide to countdown timers for email. A printed code and an emailed deadline age in the same way, and one question decides both: will this still be right a month after it ships?