> ## Documentation Index
> Fetch the complete documentation index at: https://docs.encrata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Barcode Scan

> Decode a barcode and inspect its content for security threats.

Barcode Scan decodes a base64-encoded image and checks the extracted value for suspicious content.

## Authentication

Send your API key as `Authorization: Bearer <key>`.

## Request

<ParamField body="kind" type="string" required>
  Set this value to `bar`.
</ParamField>

<ParamField body="content_base64" type="string" required>
  The base64-encoded barcode image. Do not include a data URL prefix.
</ParamField>

<ParamField body="filename" type="string">
  The original image file name.
</ParamField>

<ParamField body="stix" type="boolean">
  Set to `true` to include STIX 2.1 output when available. Defaults to `false`.
</ParamField>

## Example request

```bash theme={"theme":{"light":"github-light","dark":"vesper"}}
BARCODE_BASE64=$(base64 < barcode.png | tr -d '\n')

curl --request POST \
  --url https://api.encrata.com/api/lookup/malware/scan \
  --header "Content-Type: application/json" \
  --header "Authorization: Bearer $ENCRATA_API_KEY" \
  --data "{\"kind\":\"bar\",\"content_base64\":\"$BARCODE_BASE64\",\"filename\":\"barcode.png\"}"
```

## Example response

```json theme={"theme":{"light":"github-light","dark":"vesper"}}
{
  "success": true,
  "result": {
    "scan_id": "scan_01J9W6Q9E8PW4V9N7T3K2M1R5C",
    "kind": "bar",
    "status": "completed",
    "verdict": "clean",
    "score": 0,
    "codes": [
      {
        "format": "CODE_128",
        "text": "ENCRATA-123456"
      }
    ],
    "data_residency": "us",
    "scanned_at": "2026-10-07T09:30:00Z"
  },
  "message": "Scan completed"
}
```

## Barcode result fields

<ResponseField name="codes" type="object[]">
  Codes decoded from the image, including each code's format and text.
</ResponseField>

<ResponseField name="signals" type="string[]">
  Security signals found in the decoded content.
</ResponseField>

See [Malware Scan](/api-reference/endpoint/malware-scan) for the complete response schema and shared fields.

## Errors

The API returns `400` for invalid base64 content or an unreadable image, `401` for a missing or invalid API key, `402` when your account has insufficient credits, and `429` when you exceed a rate limit.

## Credits

A successful scan costs 1 credit. Repeating the same scan kind and content is deduplicated for billing.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.