The WIFI: format
A Wi-Fi QR code holds one line of text that starts with WIFI: and lists fields separated by semicolons, ending with two semicolons. For a typical home or office network it reads WIFI:T:WPA;S:MyNetwork;P:secret;; where T is the security type, S the network name (SSID) and P the password.
The format grew out of open-source barcode reader projects and became a de facto convention. Recent editions of the Wi-Fi Alliance’s WPA3 specification describe a closely related URI format, which adds optional fields for newer security features.
- T: security type, usually WPA, WEP, or nopass for an open network
- S: the network name (SSID), exactly as it appears, case-sensitive
- P: the password; leave it out for an open network
- H:true marks a hidden network that does not broadcast its name
Security types and special characters
The value WPA is used for WPA, WPA2 and, in practice, most WPA3 personal networks, because phones negotiate the exact protocol when they connect. WEP is outdated and insecure, and nopass is for open networks with no password. Enterprise networks that need a username and certificate are not well served by this simple format.
If the network name or password contains a backslash, semicolon, comma, colon or double quote, that character must be escaped with a backslash. A password written as pass;word, for example, is encoded as pass\;word. Getting this wrong is one of the most common reasons a Wi-Fi code scans but fails to connect.
Phone support and good practice
Built-in camera apps on iPhone (from around iOS 11) and on Android (from around Android 10) recognize Wi-Fi codes and offer to join the network. Older phones may need a separate scanner app.
The password is stored in plain text inside the code, so anyone who can scan it can read it. Guest networks are a good fit, and the code has to be regenerated whenever the password changes, since the text is fixed in the printed image.