ALL DEVELOPER TOOLS56
QR Code Reader
QR Code Reader — Scan a Code From an Image
Drop a photo or screenshot and read every code in it, decoded in this tab and never turned into a link you can tap by mistake.
About QR Code Reader
A QR code is a bitmap, so reading one back is a decoding problem, not a network one. Drop a photograph or screenshot here and the browser decodes the picture, hands the pixels to zxing-cpp compiled to WebAssembly, and searches it for every code — several, if the picture holds several. The engine is served from this site rather than the CDN its npm package points at by default, so scanning a code tells nobody that you scanned it. The part worth reading twice is what this page will not do. A decoded payload is printed as text and is never made clickable. A square looks identical whatever is inside it, which is why the stickers pasted over parking-meter codes work — so the host name is broken out into its own row, and a link carrying credentials in front of the host, a punycode lookalike or a zero-width character is named where it occurs. Wi-Fi payloads, vCards, MECARDs, calendar entries, mailto:, tel:, sms: and geo: are decomposed into labelled fields, and a two-factor enrolment secret is masked there and flagged in the raw text.
Questions
The code in my photo will not read.
Work down the causes, taking the ones the page named for your own image first. If you dropped an animated GIF or WebP, only its first frame was scanned — the browser hands back an animation's default image, so a code that appears later in the loop is simply not in the pixels that were searched, and no amount of denoising will find it; save the frame the code is on and scan that. If the code is a striped retail barcode rather than a square, switch SCAN FOR to Every format — the default searches only for QR, Micro QR and rMQR. If the photo is blurred or badly lit, turn on the extra denoising pass under IF IT WILL NOT READ. If the code runs to the edge of the frame with no white margin, no reader will get it: the quiet zone is part of the specification, not a courtesy. And if the picture is enormous, crop it down to the code — an image bigger than a browser canvas is guaranteed to hold is scaled before scanning, which the page reports, with the numbers.
Is it safe to scan a QR code from a poster or a letter I did not expect?
Scanning it here is safe; acting on it may not be. A square looks identical whatever is inside it, which is the mechanism behind stickers pasted over parking-meter codes and fake payment slips. So this page decodes and stops: the payload is printed as text, nothing is clickable, and the host name is pulled into its own row so you can read it without picking a URL apart. Three tricks are named where they occur — a username in front of the host, so paypal.com@evil.example reads as PayPal and goes elsewhere; a punycode host, where Cyrillic and Latin letters draw the same; and zero-width or right-to-left characters, which change what a string looks like without changing what it is.
Can it read ordinary barcodes, not just QR codes?
Yes — set SCAN FOR to Every format. That adds Data Matrix, Aztec, PDF417, MaxiCode, Codabar, Code 39, Code 93, Code 128, ITF, DataBar and the EAN/UPC retail family. It is not the default because it costs real time: several of those symbologies are searched line by line across the whole image, and on a 12-megapixel photo the full set took 2.9 seconds against 0.19 seconds for QR alone in our own measurements. Every run prints the time it actually took, so you never have to take that on trust. If you only ever wanted a QR code, the default is fifteen times faster and finds exactly the same square.
There are several codes in one picture — do I have to crop them apart?
No. The symbol limit is turned off, so every code in the image is decoded and each one gets its own block with its own format, its own payload and its own copy button. The header says how many were found, which matters because a photo of a page of tickets should produce a number you can check. If the codes turn out to be parts of one payload split across several symbols — structured append, which is what an encoder does when the data will not fit in one square — the page says so and names the parts that are missing, rather than showing you a fragment as though it were the whole thing.
Why does the first scan fetch about a megabyte?
That is zxing-cpp, the barcode engine, compiled to WebAssembly: 1,093,289 bytes, fetched once and then cached by the browser. It is served from this site. The npm package it comes from defaults to pulling that file from a public CDN, which would have handed a third party your IP address every time you opened the page — so the loader passes the bytes in directly and overrides the path, and a unit test fails the build if a foreign origin ever appears in that file again. The alternative was the browser's own BarcodeDetector, which costs no download and exists only in Chrome; a page built on it would work for some visitors and silently find nothing for the rest.
Is my file uploaded to a server?
No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.