Generate a QR image
Encode the entire text as one path component. Explicitly set high-contrast colors and test with multiple scanners when producing print assets.
Schemes
Use the corresponding platform parser/client library. Unknown query parameters must not silently become signed contract values or payment fields.
Smart contract links
The minimum contract form is:Visibility, a recipient Role, known role-to-Legal-ID assignments, and initial parameter values:
Signature links
tagsign:{requestor-jid},{base64url-key} asks a client to start a signature petition. The client sends <ql xmlns='https://tagroot.io/schema/Signature'> to the named party; the resulting petition uses the current legal-identity namespace urn:nf:iot:leg:id:1.0 (legacy peers may advertise the IEEE namespace).
The key is short-lived. Bind approval UI to requestor, purpose, content hash, target endpoint, Legal ID, and expiry. Declining must not create a signature.
Onboarding links
text/plain to https://DOMAIN/Onboarding/GetInfo with Accept: text/plain, Base64-decodes the response, then decrypts and validates the onboarding XML with the supplied key and IV. Current flows use AES-CBC and PKCS#7 padding; use the platform onboarding implementation because key length and one-time policy depend on the producer.
Partial onboarding can be reusable; full/recovery and transfer payloads are normally one-time and short-lived. An obinfo URI is equivalent to a credential—never log, preview, analytics-track, or sync it through an untrusted service.
Multi-purpose QR package
When the optional MultiQR package is installed,/MultiQR.md creates a landing page containing one or more labeled links or embedded media. Definitions can have an expiry, use limit, custom master, color scheme, and counter category. Script packages can call CreateMultiQR(definition, "/MultiQR.md") and receive { Image, Page } URLs.
Validate every embedded URL/media type and avoid placing secrets in a multi-purpose page: the page link can be copied even when the original QR was shown privately.