Server-rack QRs require a PIN before revealing internal Confluence or Jira pages. When the code is a paid Eternal QR, every redirect change is mirrored on-chain as a tamper-evident change log.
An unlock interstitial at /unlock/:id stands between a walk-in scan and the wiki: the destination is checked against the PIN server-side and is simply not returned until the prompt is answered, so the internal URL never reaches an unauthorised phone. Configured as paid Eternal QRs, they log every destination change immutably to the EternalRegistry contract on Base; Basic codes keep the PIN gate but no on-chain log. Workspace roles split admins from read-only support engineers.
Free tier includes 1 standard QR code. Upgrade to the paid Eternal tier for blockchain permanence and the recovery key.