← All articles

Practical guides · 9 min read

How to Share a PDF With a QR Code—and Replace the PDF Later

Share a PDF through a QR code, check access without the owner's login, and choose a stable file address or an editable short link for later updates.

By The 302.sh team ·

The file host controls the PDF and its accessA schematic QR leads through a short link to a hosted PDF. A separate direct file URL also reaches that PDF without using the short link. The file host controls document access. The QR symbol is not scannable.Keep the entrance. Update the document.Saved QRShort linkEdit targetFile hostPDF v1 → v2Access rulesDirect file URLThe direct URL can bypass the short link.
A QR code stores an address. That address can open the hosted PDF directly or go through a managed short link. File permissions belong to the host, and the direct file URL can be shared independently of the short link.

Host the PDF at an address your readers can open, then create a QR code for that address or for a short URL you control. To replace the document later, keep its address stable where the host supports that, or change the short link's destination. 302.sh manages the redirect; it does not host your uploaded PDF or grant access to a private file.

The QR pattern does not contain a copy of your PDF. If it contains a URL, the reader needs access to that URL and whatever it leads to. A file that opens for you in its editor may still ask everyone else to request permission.

Choose where the document lives and who may read it

For a public handout, product manual or menu, use your website or a file host that supports visitor access. For restricted documents, keep the required account or membership checks at the file host. A short link can make the entrance easier to share, but it cannot bypass those checks.

A stable web page is often a useful entrance. For example, a page on your own site can explain the document, show its version and provide an accessible reading option alongside a PDF download. Updating that page's download link preserves the page URL even when the PDF filename changes.

If you use Google Drive, its sharing documentation distinguishes “Anyone with the link” from “Restricted.” Organization policy may limit available options. Share the reader-facing file URL, not an editor, upload or temporary preview address. Only make a document public when its contents are intended for public distribution.

Choose a direct address or an editable entrance

QR containsHow to update laterDependency
Stable page URLUpdate the page and its PDF download link.Keep the website and exact page address available.
Direct hosted file URLReplace the file/version while preserving its public address and permissions.The host must support replacement at that same address.
Managed short URLEdit the destination to the new file or page; preserve the short hostname and slug.Keep the short link and account working as well as the file host.

If you already own a stable public page and do not need a separate visit report, a direct QR for that page may be enough. A managed entrance is useful when files move between hosts or when several printed placements need separate reports. Neither choice guarantees that a visitor's PDF viewer will immediately discard a cached copy.

Check as a reader before making the QR code

  1. Copy the intended public or reader-facing URL from the host.
  2. Open it in a session without the owner's login. For a restricted file, also test with an authorized reader account and an account that should be denied.
  3. Confirm the title, visible version, page count and key content. Check the download if downloading is part of the reader workflow.
  4. Try a phone-sized screen and the PDF viewer your audience is likely to use. Check text readability, zoom, links and accessibility; a successful download alone does not establish usability.
  5. Resolve permission prompts, broken previews and unintended edit access before distribution.

Private browsing helps remove the owner's session, but you must confirm you are actually signed out of the file host. A public HTTP response can establish file availability without account cookies; it cannot prove a mobile viewer works or that the document is accessible.

Create and keep the original QR

For a direct code, use a QR generator with the stable page or file URL. For an editable 302.sh entrance, sign in, open New link, paste the hosted PDF or page URL and save. Open the saved short link, then use its link-detail QR control to download PNG or SVG. Decode the downloaded image to confirm it contains the short URL.

Use an account-owned link for lasting print. Check expiry and other restrictions, and keep the original image with the document's maintenance record. Print a small sample and test it under the actual viewing conditions before ordering the full batch. Our QR lifetime guide explains the dependencies that need to remain available.

Replace the PDF without changing the printed entrance

Option A: keep the file or page address. Back up the current version, then use your host's supported replacement workflow. Google Drive documents Manage versions → Upload new version for files such as PDFs. This is different from deleting a file and uploading another with the same name. Check the original share URL afterward; matching filenames do not prove matching file identities or permissions.

Option B: keep the short address. Upload the new PDF, verify visitor access, and save its URL as the existing short link's destination. Keep the old hostname and slug. The 302.sh destination-edit walkthrough shows the actual controls and an earlier maker-run test. It used web pages, not PDFs, and recorded an old target briefly appearing after Save.

For either option, open the original QR again and verify a visible version marker inside the document. If the old version persists, compare the final URL, download a fresh copy and check the host's caching/version behavior. A saved setting or a changed filename is not proof that the distributed entrance now opens the correct document.

A small, reproducible PDF example

We created two one-page fictional workshop handouts: version 1 (PDF) says Room 2; version 2 (PDF) says Room 4. They contain no customer information and are retained as separate files so you can inspect both versions.

On September 16, 2026, we tested both update patterns with a local HTTP fixture on a Mac. For each pattern we generated one QR image, decoded it with macOS Vision, fetched the document without cookies or an Authorization header, changed the fixture, then fetched through the same decoded address. The saved QR bytes were unchanged and the returned PDF hash and visible room changed.

Local entry pathBeforeChange madeAfter
/handout.pdfVersion 1, Room 2Serve version 2 at the same path.Same entry path; version 2, Room 4.
/entry302 redirect to the version 1 file.Point the fixture redirect at the version 2 file.Same entry path; version 2, Room 4.

Scope: these are loopback test paths, not public demo routes. The fixture disabled caching to isolate URL and file replacement. It was not a live 302.sh redirect, Google Drive upload, browser/PDF-viewer test, phone scan, physical-print test or CDN propagation measurement. Software decoding establishes what these saved images encode; it does not establish real-world scan reliability.

The old version remained retrievable at its separate file URL after the redirect changed. A deliberately denied fixture URL returned 403 without credentials. That denial demonstrates only the test fixture's response, not the security of a real document host. Check your chosen host with actual allowed and denied reader sessions.

Keep a version and rollback record

Download the blank PDF version record (CSV). Record the document version, hosted file URL, public entry URL, access-check result, replacement date and owner. Keep prior file bytes or a pinned host version separately; a record containing only URLs cannot recover overwritten content.

Before replacing a document, decide what recovery means. If the new content is wrong, restore the prior file or short-link target and test the original code again. If the old document must be withdrawn, remove or restrict it at the host too. Keep this record with the QR artwork and hand it over when responsibility changes.

What changing or protecting the short link cannot undo

A password-protected short link gates that entrance. Anyone with a public direct PDF URL can bypass it. Changing or deleting the short link does not revoke the direct file URL, and changing file permissions does not recall copies readers already downloaded.

For confidential material, enforce access at the document host and share it only with the intended audience. For public instructions that change often, show the current version clearly and make it easy to return to the maintained entrance. Restaurants can use the separate menu maintenance workflow for signs across tables and counters.

What is included in 302.sh?

Free allows 5 new links per UTC month and up to 50 owned links, with 5 custom slugs per month of at least 6 characters. Deleting a link does not refund its monthly creation allowance.

Free includes 2,000 analytics events per month and 90-day retention. Reaching that analytics allowance stops additional tracking, not redirects. Link deletion, owner-set limits and safety enforcement can still stop redirects. Branded domains require a paid plan and completed domain setup. See current plans and limits.

Try the workflow

Explore the dashboard demo, or create a short link using a destination you own or are authorized to share. Verify the destination before distributing it.

Keep reading