All packages
QR for Laravel
Sensitivity & caching
Every payload has a sensitivity that decides whether its matrix may be memoised, its SVG cached, and how HTTP responses are cached:
| Sensitivity | Payloads | Memo / SVG cache | HTTP |
|---|---|---|---|
Public | text, URLs | yes | public, ETag |
Personal | payments, e-mail, phone, SMS, vCard, geo | no | private, ETag |
Secret | otpauth, Wi-Fi, otpauth/Wi-Fi-looking text or opted-in URLs | no | no-store, no ETag |
Overriding the default
->sensitivity() raises or lowers the default; 2FA seeds stay Secret:
use RoundlyConsulting\Qr\Enums\Sensitivity;
// A guest Wi-Fi poster in the lobby may be served publicly
return Qr::wifi('Clinic Guest', 'guest-password')->sensitivity(Sensitivity::Public);
// A payment code printed on a public invoice page
return Qr::epc($payment)->sensitivity(Sensitivity::Public);
// 2FA seeds stay Secret — the sensitivity of an otpauth payload is locked
Qr::otpauth($setup->provisioningUri)->svg();Memo and SVG cache
- Matrix memo — an in-process LRU of encoded matrices for public payloads (memo.entries, default 64; 0 disables). Bounded, and never holds secret or personal data — safe under Octane.
- SVG cache — opt-in storage of rendered SVG for public payloads in any Laravel cache store. The key includes the resolved title and description, so a translated default title never crosses locales; values are plain JSON, never unserialised PHP objects.
QR_CACHE=true
QR_CACHE_STORE=redisSafe by default
- Exception messages carry the type, field and reason — never a payload value (IBANs, names and amounts included).
- Work is bounded: encoder input ≤ 7089 bytes, SVG size ≤ 8192, margin ≤ 64, EPC input ≤ 331 bytes, otpauth URIs ≤ 1024 bytes, PAY by square input ≤ 4296 characters.
- URLs are limited to http and https unless you opt in to more schemes.
- php artisan about shows configuration only, never the cache store’s name.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.