Authentication

API keys

Every request authenticates with an app API key in the Authorization header. Keys are created in the developer console and belong to one app.

Authenticated request
export QUIC_API_KEY="qk_sb_..."   # your sandbox key

curl https://api.quic.chat/platform/v1/ping \
  -H "Authorization: Bearer $QUIC_API_KEY"

Key format#

qk_sb_… is a sandbox key and qk_live_… a live key. QuiC stores only a hash: the full key is shown once, when you create it. Lost it? Create a new one and revoke the old.

Environments
KeyWorks when the app isCan reach
qk_sb_sandbox, internal live, public liveAccepted testers only
qk_live_internal live or public liveOpted-in users your access level allows

Up to 2 active keys per environment, so you can rotate without downtime: create the new key, deploy it, then revoke the old one. The console shows when each key was last used.

Scopes#

Keys get every scope by default. A call without the right scope fails with 403 insufficient_scope.

Scopes
ScopeAllows
messages:sendPOST /messages
messages:readGET /messages/:id, GET /media/:id
media:writePOST /media
consents:readGET /users/:appUserId, GET /consents
optin_links:createPOST /optin-links
profile:writePATCH /business-profile
webhooks:manage/webhooks, /webhook-deliveries
templates:manageReserved for message templates (coming later)

Headers#

  • Base URL: https://api.quic.chat/platform/v1. HTTPS only.
  • Responses carry QuiC-Request-Id (quote it to support) and QuiC-Version: 2026-10-01.
  • Idempotency-Key is required on POST /messages and honoured on every POST. See idempotency.
  • Rate-limit headers: RateLimit-Limit, RateLimit-Remaining, and Retry-After on 429.