Pharma API QR Code Generator
All eleven particulars required by G.S.R. 20(E), free.
This builds QR codes. It is not a traceability system. It stores nothing, keeps no records, and produces no audit trail. G.S.R. 20(E) requires the code on the label; whether your wider process satisfies the rules is a question for your regulatory adviser and the notification itself, not for a web page. Verify the encoded data against the label before printing a production run.
Shown larger than it prints, so you can test it with a phone. Drum 1 of 10. Version 9, 53 × 53 modules at level M, 247 characters. At the 30 mm print size that is 0.49 mm per module.
At 0.49 mm per module, 30 mm is too small for this much data. Print it at or larger.
What drum 1 actually encodes
PC:API-PCM-500 * API:PARACETAMOL * MFR:EXAMPLE PHARMA PVT LTD * ADR:PLOT 42. MIDC INDUSTRIAL AREA. PUNE 411018. INDIA * LOT:B2401 * QTY:500 KG * MFD:260115 * EXP:290114 * LIC:MFG/API/2019/0042 * STG:STORE BELOW 25 C. PROTECT FROM LIGHT * DRUM:1/10
B2401
B2401
B2401
B2401
B2401
B2401
B2401
B2401
B2401
B2401
How the Pharma API QR Code Generator works
India's G.S.R. 20(E) requires a QR code on the label of every active pharmaceutical ingredient manufactured in or imported into the country, carrying eleven stated particulars. This builds that code with all eleven fields, checks the SSCC check digit, and prints a label sheet for a run of batches. It runs in your browser and nothing is uploaded.
Also known as: GSR 20(E) QR code generator · QR code for API manufacturers · API label QR code India · active pharmaceutical ingredient traceability QR · Drugs Rules QR code for API · free pharma QR code software
What the notification says
G.S.R. 20(E) was notified by the Ministry of Health and Family Welfare on 18 January 2022 and became mandatory on 1 January 2023. It amends the Drugs and Cosmetics Rules 1945 and applies to every active pharmaceutical ingredient manufactured in or imported into India.
The requirement is a QR code on the label at each level of packaging, storing data readable by a software application. Eleven particulars are listed as the minimum: unique product identification code, name of the API, brand name if any, name and address of the manufacturer, batch number, batch size, date of manufacturing, date of expiry or retesting, serial shipping container code, manufacturing or import licence number, and special storage conditions where any apply.
The stated purpose is traceability: allowing an ingredient to be followed through the supply chain, and making it harder for spurious material to enter it. That intent matters for interpretation, because a code that technically contains the fields but cannot be read by anyone downstream does not serve it.
The part the rule does not specify
The notification says what the code must contain. It does not say how the data should be structured inside it, and that omission is responsible for most of the confusion around implementation.
Two approaches are in common use. Labelled plain text puts each particular on its own line, which means anyone scanning with an ordinary phone camera sees readable information immediately, including an inspector or a customer with no special software. Structured formats such as JSON parse cleanly into a receiving system and look like code to anyone without one.
Neither is prescribed and both satisfy a plain reading of the requirement. The choice is really about who is expected to scan it. For material moving between businesses that have agreed a format, structured data is better. For anything that might be scanned by someone outside that arrangement, readable text is safer.
Why GS1 identifiers cannot carry the whole list
GS1 Application Identifiers are the standard way of encoding supply chain data, and a good deal of guidance around this rule assumes they are the answer. They are only part of it.
GS1 defines identifiers for several of the required particulars: 01 for the product identifier, 10 for batch or lot, 11 for production date, 17 for expiry, and 00 for the serial shipping container code. Those cover five of the eleven.
There is no standard identifier for the manufacturer's address, the batch size, the licence number or the storage conditions. Which means a pure GS1 element string cannot hold everything the notification requires, and any implementation claiming otherwise is either omitting fields or using private identifiers that nobody else will interpret. That is the practical reason structured text remains the common choice for the API code itself, whatever else appears elsewhere on the label.
Dates, and the ambiguity worth avoiding
Two of the eleven fields are dates, and the notification does not prescribe a format. That leaves room for a genuinely dangerous ambiguity: 03/04/2026 is the third of April in India and the fourth of March in the United States, and API moves internationally.
ISO format, four digit year then month then day, removes the problem entirely and sorts correctly as text. It is the format used here for that reason.
The expiry field carries a second subtlety. The rule says date of expiry or retesting, and for many APIs a retest date is what applies: the material does not expire so much as require re-analysis before further use. Labelling a retest date as an expiry date understates the usable life and can cause perfectly good material to be discarded, so the distinction is worth carrying through into the code rather than flattening.
The serial shipping container code
SSCC is a GS1 identifier for a logistics unit: a pallet, a drum, a shipping container. It is eighteen digits, and the last of them is a check digit calculated from the preceding seventeen using the same modulo 10 weighting as a GTIN.
It identifies the container rather than the product, which means it belongs on shipping-level packaging rather than on every unit. A manufacturer applying the same SSCC to every drum in a consignment has misunderstood what it is for: each logistics unit gets its own.
Getting the check digit wrong produces a code that any GS1-aware system downstream will reject, and the failure typically surfaces at a customer's goods-in rather than at your own dispatch. That is why the digit is calculated here rather than accepted on trust.
Printing it so it survives the warehouse
API labels live on drums, sacks and fibre containers, which are handled, stacked, dragged and stored in conditions that paper does not enjoy. That changes the printing decisions from the ones that suit a retail box.
Error correction should be Q or H rather than the M that suits a clean surface. Those levels tolerate roughly 25% and 30% damage respectively, which is the difference between a scuffed label that still scans and one that does not.
Module size matters more than overall dimension. A physically large code with a small module is harder to scan than a smaller one with generous modules. Somewhere around 0.5 mm per module is a reasonable floor for industrial handheld scanners, which at typical data volumes puts the printed code in the 25 to 40 mm range.
Then the material. Thermal transfer onto synthetic label stock survives handling and solvents in a way that direct thermal on paper does not, and direct thermal labels fade with heat, which is exactly what a warehouse in summer provides.
What this tool is not
It generates a code. It does not store anything, keep records, or produce an audit trail, and those absences are deliberate rather than incidental.
Traceability in the sense the notification intends is a process rather than an image: knowing which code went on which drum, which drum went to which customer, and being able to reconstruct that months later when a question arises. Commercial platforms exist for exactly that, they integrate with ERP and labelling systems, and for a manufacturer at any scale they are the right answer.
What was missing was the free end of that spectrum. A small manufacturer producing a few batches a month needs a correct code and a printable sheet, and was being quoted for an enterprise deployment. This closes that gap and does not pretend to close the other one.
The regulation itself is the authority on what compliance requires, and a regulatory adviser is the person to interpret it for your operation. Nothing on this page is legal advice, and the sensible use of it is to generate the code, verify what it encodes against your label, and keep the records elsewhere.
Frequently asked questions
What does G.S.R. 20(E) actually require?
Notified on 18 January 2022 and mandatory from 1 January 2023, it amends the Drugs and Cosmetics Rules 1945 to require a QR code on the label of every API at each level of packaging. The code must store, at minimum, eleven particulars: unique product identification code, name of the API, brand name if any, name and address of the manufacturer, batch number, batch size, date of manufacturing, date of expiry or retesting, serial shipping container code, manufacturing or import licence number, and any special storage conditions.
What format should the data be in?
The notification specifies what the code must contain and not how it should be encoded, which is the single most confusing part of implementing it. This offers labelled plain text, which any phone camera renders readably, and JSON, which parses cleanly into a receiving system. Both carry all eleven fields.
Why not use GS1 Application Identifiers?
Because they do not cover the full list. GS1 defines identifiers for the product code, batch, dates and SSCC, and has none for manufacturer address, batch size, licence number or storage conditions. An element string alone therefore cannot carry the eleven particulars, which is why plain structured text is the practical choice for the code itself.
Is this a compliance system?
No, and the distinction matters. It generates a code. It stores nothing, keeps no records and produces no audit trail, so it cannot demonstrate anything to an inspector. What it does is remove the cost of generating a correct code, which for a small manufacturer is the part that was disproportionately expensive.
What size should the printed code be?
Large enough for the scanner and the surface. On a drum or sack label, 25 to 40 mm is typical, and the module size matters more than the overall dimension. Anything printed on rough or curved packaging should use error correction level Q or H, since those tolerate 25% and 30% damage respectively.
Do I need an SSCC?
The notification lists it among the particulars, and it applies to shipping containers rather than to every level of packaging. Where you use one, it is an 18 digit GS1 code whose final digit is calculated from the other seventeen. This checks that digit, because an SSCC with the wrong one is rejected by any GS1-aware system downstream.
Can I generate codes for a whole production run?
Batch mode takes one line per batch with the batch number, size and dates, reuses everything else from the fields above, and lays the codes out as a printable sheet. Lines that are missing required fields are listed separately rather than skipped silently.
Is my batch data sent anywhere?
No. The QR encoding runs entirely in this page and the tool makes no network request as you type. You can confirm it by disconnecting from the internet after the page loads and watching it continue to work.