PayNowQR REST API
Create real, payable PayNow QR codes from a secure server-side application. Payments go directly to the PayNow profile linked to your API key; FoodLine does not receive, hold, settle, reconcile, or confirm payments.
Keep API keys on your server. Never place a pk_live_⊠key in browser JavaScript, a mobile app bundle, a public repository, or a URL. Public browser CORS is not enabled.
Authentication
Create a key from Dashboard â API. Send it in the HTTP Authorization header:
Authorization: Bearer pk_live_xxxxx
The complete key is shown once. Regenerating a key immediately revokes the old one. Each active PayNow profile supports one active API key.
Create a QR code
POST /paynow-qr/api/v1/qr-codes
| Field | Required | Values |
|---|---|---|
| amount | Yes | Decimal string, for example 128.50 |
| reference | Yes | Up to 25 supported characters |
| colour | No | BLACK, NAVY, or PURPLE |
| size | No | 512, 1024, or 2048 |
| expiry | No | Omit for no expiry (the default), or use YYYY-MM-DD from today through five years |
cURL
curl -X POST https://www.foodline.sg/paynow-qr/api/v1/qr-codes \
-H "Authorization: Bearer pk_live_xxxxx" \
-H "Content-Type: application/json" \
-d '{"amount":"128.50","reference":"INV-10231","colour":"BLACK","size":512}'
PHP (server-side)
<?php
$ch = curl_init('https://www.foodline.sg/paynow-qr/api/v1/qr-codes');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer '.getenv('PAYNOWQR_API_KEY'),
'Content-Type: application/json'
],
CURLOPT_POSTFIELDS => json_encode([
'amount' => '128.50', 'reference' => 'INV-10231'
])
]);
$response = json_decode(curl_exec($ch), true);
Assets
The creation response returns 15-minute signed png_url, svg_url, and pdf_url values. Signed URLs contain no API key and are recommended for direct display in a browser, customer-facing page, mobile app, or POS screen. Generated assets include a red âby FoodLine - Singapore biggest catering platformâ attribution. It links to https://www.foodline.sg/ in SVG and PDF output. PNG is a bitmap and cannot contain a hyperlink, but the attribution remains visible. The watermark cannot currently be removed; a future paid option may allow its removal.
<img src="SIGNED_PNG_URL" alt="PayNow QR">
For longer-lived server-to-server access, call the authenticated download paths with the same Bearer header:
GET /paynow-qr/api/v1/qr-codes/qr_xxxxx/png GET /paynow-qr/api/v1/qr-codes/qr_xxxxx/svg GET /paynow-qr/api/v1/qr-codes/qr_xxxxx/pdf
Any active key belonging to the same account can retrieve that accountâs active QR history. Cross-account requests return 404.
Embedding a PayNow QR in your existing invoice
The API lets your system generate a customised PayNow QR and embed it directly in the payment section of an invoice you already create. Set the QR amount to the amount payable and its reference to the invoice number. The completed invoice will contain the QR image itself, allowing the customer to scan and pay without manually entering those details.
- When your server creates an invoice, call
POST /paynow-qr/api/v1/qr-codeswith the amount payable and invoice number. - Read the PNG or SVG download path returned by the API.
- Using your API key on the server, download the QR image.
- Pass the image data to your existing invoice renderer and position it in the invoiceâs payment section.
- Generate and send the completed HTML or PDF invoice containing the embedded QR code.
<?php
$assetUrl = 'https://www.foodline.sg'.$response['downloads']['svg'];
$asset = curl_init($assetUrl);
curl_setopt_array($asset, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer '.getenv('PAYNOWQR_API_KEY')
]
]);
$qrSvg = curl_exec($asset);
// Embed $qrSvg in the payment section of your existing invoice.Use SVG for the clearest result in printed or PDF invoices, or PNG if your invoice renderer does not support SVG. Embed the downloaded image data in the final invoice instead of storing a temporary signed URL. The separate PDF asset produced by PayNowQR is intended as a standalone payment page and is not needed when adding the QR to your own invoice layout. Keep the API key on your server, and scan-test the completed invoice to confirm the recipient, amount and reference before sending it to customers.
Quota and rate limits
Each account has 100 successful generations per Singapore calendar month, shared by signed-in web and API generation. It resets at 00:00 on the first day of the month in Asia/Singapore. Deleting history does not restore usage. API keys are limited to 60 requests per minute.
Errors
{
"success": false,
"error": { "code": "VALIDATION_ERROR", "message": "Amount is required." }
}400 malformed request; 401 missing/invalid/revoked key; 404 unavailable QR; 422 validation error; 429 quota or rate limit; 500 unexpected failure.
Operational safety
Scan-test every QR and confirm the recipient shown by the payerâs bank before distribution. PayNowQR cannot detect whether payment was completed, so QR history is not payment history.






