Skip to content
QRMakery
Comparisons16 min read

Static vs Dynamic QR Codes

A static QR code generator puts your destination inside the pattern. A dynamic QR code puts someone else's redirect there instead. Here is what that single difference costs and buys, measured on real codes.

Written by the QRMakery team

Published

A static QR code holding this article's address. Made by the generator on this site and read back by a decoder before it was published.
Version 6 · 49 modules · 19.6 mm minimum print width
On this page9 sections
  1. 01The Only Difference That Matters
  2. 02Static vs Dynamic, Side by Side
  3. 03What the Short URL Is Worth in Print
  4. 04Which QR Code Types Can Be Dynamic at All
  5. 05How to Choose, Without a Feature Matrix
  6. 06The Middle Option Nobody Sells You
  7. 07Four Claims to Be Sceptical About
  8. 08What QRMakery Makes Today
  9. 09Common Questions
A QR pattern with a direct route to a webpage and a second route through a redirect server

The Only Difference That Matters

Every comparison of static and dynamic QR codes describes them as two kinds of QR code. They are not. There is one kind of QR code, and the question is only whether the pattern contains your destination or a redirect that points at it. Neither word appears anywhere in ISO/IEC 18004, the standard that defines the symbol.

A static code containshttps://example.com/menus/autumn-2026/dinner

The camera reads your URL and goes there. Nobody is in the middle, nothing is logged on the way, and the code decodes to that string for as long as the image survives. Change your mind about the destination and you reprint.

A dynamic code containshttps://provider.example/7Kd2Qa

The camera reads the provider’s URL, the provider records the scan and answers with a redirect to wherever you have currently pointed that slug. Change the destination in a dashboard and every printed copy follows.

So a dynamic QR code is a static QR code of a short URL, plus a redirect service you are renting, plus a log. That is not a criticism. The redirect is genuinely useful and the log is the only way to count scans. It is worth knowing that everything you are buying sits outside the symbol, because it explains every trade-off below.

Static vs Dynamic, Side by Side

The last column is our reading of who wins the row, not a scoreline. Two rows decide most real cases: whether the destination can change, and whether you need scan numbers. If you need either, stop reading the rest and get a redirect.

AspectStatic QR codeDynamic QR codeEdge
What the modules encodeThe destination itself: the full URL, the network credentials, the contact card.A short redirect URL owned by the provider, which forwards to your real destination.Depends
Changing the destination after printingImpossible. The image is the data, so a new destination means a new code and a reprint.Edit the target in a dashboard and every printed code follows, instantly.Dynamic
Scan analyticsNone from the code itself. You can only measure what the destination sees.Scan counts, times, rough location and device, because every scan passes through the provider.Dynamic
Ongoing dependencyNone. Once the file is exported it works with nobody's servers involved, including ours.Total. The redirect is a live service; if the account lapses or the provider dies, printed codes stop resolving.Static
LifespanAs long as the destination exists. The symbol itself cannot expire: there is nothing to expire.As long as you keep paying and the provider keeps the slug alive. Free tiers are where 'expired QR code' stories come from.Static
Privacy for the people scanningThe camera goes straight to the destination. No third party sees the scan.Every scan is logged by the provider before the redirect. That is the feature, and it is also the cost.Static
Works without a networkWi-Fi, contact cards, plain text and calendar events all resolve offline, on the phone.Needs a working connection for the redirect hop, even when the payload would not have.Static
Print densitySet by your URL. A long tracked link means more modules, so a larger minimum print size.Fixed and short, so the symbol stays sparse whatever the destination, measured below.Dynamic
Editing the destination later without a providerAvailable: encode a short URL on your own domain and change the redirect server-side.Same mechanism, someone else's domain. You are renting the slug rather than owning it.Static
CostFree here, with no account and no cap on how many you make.A subscription, usually priced per code or per scan volume.Static
Best fitAnything permanent or unattended: packaging, signage, business cards, equipment labels, Wi-Fi.Anything campaign-shaped: posters with a changing offer, print runs you cannot recall, tests you want to measure.Depends

What the Short URL Is Worth in Print

This is the one advantage of dynamic codes you can actually see, and it is usually credited to the wrong thing. A QR symbol grows in steps as the text gets longer: more characters means a higher symbol version, which means more and therefore smaller modules at the same physical size, so a larger minimum print width before scanners start struggling. A hundred and thirty characters of campaign URL costs you real millimetres.

Two printed QR patterns showing large sparse modules beside small dense modules on a cutting mat with a ruler
Shorter payloads use fewer, larger modules. Longer payloads need a larger printed symbol to keep each module readable.
The same menu page, encoded four ways. Version, module count and minimum print width are measured at build time by this site’s own encoder, at a four-module quiet zone.
What the code encodesCharactersVersionModules acrossMin width, mediumMin width, high
Static, full campaign URLStatic✓ decoded backhttps://www.example.com/menus/autumn-2026/dinner?utm_source=table-tent&utm_medium=qr&utm_campaign=autumn-menu&utm_content=table-12The URL an analytics team hands you. Nothing is wrong with it, and it is why some static codes look so dense.13085722.8 mm27.6 mm
Static, tidy URL, no tagsStatic✓ decoded backhttps://www.example.com/menus/autumn-2026/dinnerSame page, tracking dropped. A third of the characters, and it shows.4844116.4 mm19.6 mm
Static, redirect on your own domainStatic✓ decoded backhttps://example.com/menuA static code pointing at a path you control and can repoint server-side. Editable in practice, owned outright.2423313.2 mm14.8 mm
Dynamic, provider redirectDynamic✓ decoded backhttps://prv.example/7Kd2A typical provider slug, exactly as long as the row above, and therefore identical in every measured column.2423313.2 mm14.8 mm
130 characters · version 8 · 57 modules
24 characters · version 2 · 33 modules

Both codes open the same menu. The short one is 24 modules narrower, which at high error correction is 12.8 mm off the minimum print width, about 46% smaller before reliability starts to suffer. That is the whole density argument for dynamic codes, and the third row of the table gets it without a subscription.

The rows are ordered by length, and the two shortest are identical in every measured column even though one is a static code on your own domain and one is a provider’s dynamic slug. Density follows character count and nothing else. If your codes look dense, the fix is a shorter URL, not a subscription.

Which QR Code Types Can Be Dynamic at All

Dynamic codes were designed around one payload: a web link. Every other type gets a “dynamic” version by being turned into a web link, so the code opens a hosted page that offers you the Wi-Fi details or the contact card instead of the phone handling them itself. Sometimes that is a fair trade. Often it converts something that worked offline into something that needs signal, and twice in this table it is a bad idea outright.

Every type below is static-first. Links point at the tools that are live here today; the rest are being built, and the generator covers links and text in the meantime.
QR code typeWhat a static code encodesDynamic version
Website linkLive hereThe URL, character for character.Dynamic fitsThe only payload dynamic codes were really designed for. Everything below inherits the idea by analogy.
Branded or logo codeLive hereAny payload. Branding is a visual layer, not a data type.SometimesBranding is orthogonal. A logo needs error-correction headroom, and a short redirect URL leaves more of it, the one real overlap.
Plain textLive hereThe text, shown by the scanner as-is.No benefitA dynamic version has to host a page to show the text, which turns an offline payload into a web request.
Wi-Fi networkPlanned toolSSID, security type and passphrase, read by the phone itself.AvoidRouting guest Wi-Fi through a redirect means credentials sit on a server and the code fails for anyone not yet online.
Contact card (vCard)Planned toolName, phone, email and address as a vCard the phone saves.SometimesDynamic is worth it only if you want the details to stay editable after the cards are printed, at the cost of needing signal to save a contact.
Email, SMS or WhatsAppPlanned toolA mailto:, sms: or wa.me address with an optional message.No benefitThe phone's own apps handle these schemes. A redirect adds a hop and a tracking record, and changes nothing about the result.
Calendar eventPlanned toolEvent title, time and place, added without a download.SometimesUseful when a date might move, but a rescheduled event usually needs a message to attendees rather than a silently edited code.
Map locationPlanned toolCoordinates, opened by the phone's map app.No benefitCoordinates do not change. If the venue moves, the address on the poster is wrong too.
App downloadPlanned toolOne store URL, so one platform gets the wrong link.Dynamic fitsThe strongest non-campaign case for dynamic: the redirect can read the device and send iOS and Android to different stores.
PDF, image or filePlanned toolThe URL where the file is hosted. The file is never in the code.Dynamic fitsHosting is the product here. Whether it is called dynamic or not, a server is serving the file and can count the requests.
Campaign link with UTMsLive hereThe full tagged URL, which is what makes these codes dense.Dynamic fitsTags can be rewritten mid-campaign without a reprint, and the symbol stays sparse. Measured in the density table above.
Payment or crypto addressPlanned toolThe payment request or wallet address.AvoidNever put a redirect between a payer and an address. Whoever controls the redirect can change the payee, and this is an actively exploited fraud.

How to Choose, Without a Feature Matrix

Ask one question first: how much would it cost you if the printed code pointed at the wrong place next year? If the answer is “nothing, that cannot happen”, static is finished business. If it is “a reprint of forty thousand cartons”, you are buying a redirect and the price of it is trivial by comparison.

Static Is the Right Answer When

  • The destination is permanent: a homepage, a Wi-Fi network, a contact card, a manual for a product you still sell.
  • The code is going somewhere you cannot recall or reprint cheaply: moulded into packaging, etched on equipment, printed in a book.
  • It must work with no signal, or with no third party in the middle. Wi-Fi and payment codes are both in this bucket.
  • You want no subscription attached to something physical and long-lived, and no dependency on a company outliving your print run.
  • You need thousands of unique codes and per-code analytics is not the point: asset tags, seat numbers, serials.

Pay for Dynamic When

  • The destination is genuinely uncertain: a seasonal menu, an event page, an offer that rotates, a link you know will move.
  • Scan counts are part of the decision: which poster site works, whether the table tent beats the receipt.
  • The print run is large and already out in the world, so a broken link would otherwise mean a reprint.
  • One code must serve different people differently: iOS versus Android, or language by region.
  • The code fronts a file that has to be replaced later while the printed asset stays put: a price list, a spec sheet, a manual.

The Middle Option Nobody Sells You

You can have an editable destination without renting one. Encode a short path on a domain you already own and put the redirect behind it yourself. The printed code is static. It never expires, needs no account and nobody can switch it off, while the destination stays as editable as any dashboard would make it. It is four steps.

A printed QR plaque connected through an owned routing switch to several interchangeable webpages
Keep the printed code fixed. Change the destination at a short URL on a domain you control.
  1. 1Pick a short, human path on your own domain.example.com/menu, not example.com/campaigns/2026/autumn-dinner-menu-v3. Short keeps the symbol sparse, and it is also what people type when the camera fails them.
  2. 2Point it at the real destination with a server-side redirect.Use a 302 rather than a 301: a permanent redirect gets cached by browsers and CDNs, which is exactly what you do not want on something you intend to repoint. Every host, CMS and CDN can do this without code.
  3. 3Encode that short URL, not the destination.This is the step people skip. Once the long URL is in the pattern, it is in the pattern forever.
  4. 4Keep your UTM tags on the redirect target, not in the code.The redirect can add or rewrite the tracking parameters server-side, so your analytics stay intact and the symbol stays small. Change the campaign whenever you like.

What this does not give you is a count of scans that never reach the page, or a dashboard your marketing team can use without you. If those matter, a dynamic provider is worth the money. If they do not, you have just avoided a permanent dependency on one.

Four Claims to Be Sceptical About

Static QR codes expire.
A static code has no expiry mechanism: the destination is inside the image, and no server is consulted to resolve it. What expires is a free plan wrapped around a dynamic redirect, which is the opposite arrangement. If a code stopped working after a trial ended, it was dynamic.
Dynamic QR codes scan better.
Partly true, for a reason that has nothing to do with being dynamic: their redirect URLs are short, so the symbol has fewer modules. Encode a short link in a static code and you get exactly the same benefit, and the table above measures it. What dynamic codes add at scan time is a network round trip, which is slower and can fail.
You need a dynamic code to brand it, add a logo or change the colours.
Branding is a rendering choice and applies to both identically. It is bundled into paid plans, which makes it look like a dynamic feature. The colour and logo controls here are free and work on static codes.
Dynamic is the modern option, so it is the safe default.
It is the option that creates a recurring bill and a single point of failure for something already printed. It earns that when the destination really might change or the numbers really get used. For a Wi-Fi code by the till, it is a liability with a subscription attached.

What QRMakery Makes Today

Static codes, and only static codes. They are generated in your browser, the link never reaches a server, every code is decoded back before the download unlocks, and there is no account. That is the half of this comparison we can offer for free and keep free. A static code costs us nothing to keep working, because we are not keeping it working.

Dynamic codes, editable destinations and scan analytics are on the roadmap as a paid feature, for the same reason: a redirect that must answer a camera in five years’ time is a running cost, and pretending otherwise is how free dynamic codes end up switched off. Until then, if you need editability today, use the own-domain redirect above with a static code, which is the better engineering answer anyway, or use a dynamic provider and come back for the printing and branding work.

Common questions

What is the difference between a static and a dynamic QR code?

Only what the modules contain. A static code encodes the destination itself, so a scanner reads your URL directly out of the pattern. A dynamic code encodes a short URL belonging to a provider, which receives the scan, records it and forwards the phone on to wherever you have currently pointed it. That single indirection is where every difference comes from: editability and analytics on one side, independence and offline operation on the other. Both are ordinary QR codes to the camera, and neither is a different standard.

Do static QR codes expire?

No. There is no expiry field in a QR symbol and no server involved in resolving one, so a static code keeps decoding to the same text forever. It stops being useful only if the destination it names stops existing: a dead URL, a renamed Wi-Fi network. Stories about QR codes expiring are almost always about dynamic codes on a free or lapsed plan, where the provider's redirect was switched off.

Can I change where a static QR code points after printing?

Not in the code itself, but you can plan for it. Encode a short URL on a domain you control, such as example.com/menu, and put a server-side redirect behind it. The printed code never changes, and you can repoint that redirect whenever you like. That gives you the editability of a dynamic code without renting the slug from anyone, and it is the approach worth taking before a large print run.

Are dynamic QR codes easier to scan?

Their symbols are usually sparser, because a provider's redirect URL is short and your real destination might be a hundred characters of campaign tracking. Fewer characters means a lower symbol version, fewer and therefore larger modules, and a smaller minimum print size. That advantage comes from the short URL and not from being dynamic: a static code carrying a short link is identical in density. Against it, a dynamic code needs a network round trip to resolve, so it is slower and can fail where a static one would not.

Which is better for a restaurant menu?

It depends on whether the menu URL is stable. A permanent page at example.com/menu that you edit in place is best served by a static code, which then needs no subscription for as long as the table tents last. If instead you publish a new PDF each season at a new address, a dynamic code (or a redirect on your own domain, which behaves the same way) saves you reprinting every table.

Can I get scan analytics without a dynamic QR code?

You can measure most of what matters. Add UTM parameters to the encoded URL and your existing web analytics will attribute the visits, including different parameters per poster or per location so you can compare them. What you cannot get is a count of scans that never reached the page, and you pay for the tags in symbol density. A redirect on your own domain gets you server-side counting too, without a third party.

Does QRMakery make dynamic QR codes?

Not yet. Everything this site generates today is static, produced in your browser and decode-tested before download, with no account and nothing uploaded. Dynamic codes with editable destinations and scan analytics are on the roadmap as a paid feature, because unlike static generation they need servers that keep running. If you need editable destinations today, either use a redirect on your own domain with a static code, or use a dynamic provider. This guide is meant to be honest about which is which.

Can a static QR code be converted into a dynamic one later?

The printed code cannot be converted, because the destination is physically in the pattern. What you can do is make the URL it already encodes into a redirect: if it points at a page on your own domain, put a redirect there and the code becomes editable in effect. If it points directly at a long third-party URL, the only route is a new code and a reprint, which is the argument for encoding your own short URL from the start.

Is one of them more secure?

Static codes have a smaller attack surface: what you scan is what you get, and there is no intermediary that could be repointed. A dynamic code's destination can be changed by anyone with access to the account, which is a real risk for payment, login or credential codes, and why a redirect should never sit between a payer and a wallet address. Dynamic providers can also offer things static cannot, such as switching off a code that turns out to be abused. For anything security-sensitive and physical, prefer static; for a campaign link, the redirect risk is manageable.

Make a Static Code That Will Still Work in Ten Years

Paste a link, ideally a short one on your own domain, and download an SVG. No account, no subscription, nothing uploaded, and no way for anyone to switch it off.

Open the generator
All guides