Authentication
API keys
Every request authenticates with an app API key in the Authorization header. Keys are created in the developer console and belong to one app.
export QUIC_API_KEY="qk_sb_..." # your sandbox key
curl https://api.quic.chat/platform/v1/ping \
-H "Authorization: Bearer $QUIC_API_KEY"Key format#
qk_sb_… is a sandbox key and qk_live_… a live key. QuiC stores only a hash: the full key is shown once, when you create it. Lost it? Create a new one and revoke the old.
| Key | Works when the app is | Can reach |
|---|---|---|
qk_sb_ | sandbox, internal live, public live | Accepted testers only |
qk_live_ | internal live or public live | Opted-in users your access level allows |
Up to 2 active keys per environment, so you can rotate without downtime: create the new key, deploy it, then revoke the old one. The console shows when each key was last used.
Scopes#
Keys get every scope by default. A call without the right scope fails with 403 insufficient_scope.
| Scope | Allows |
|---|---|
messages:send | POST /messages |
messages:read | GET /messages/:id, GET /media/:id |
media:write | POST /media |
consents:read | GET /users/:appUserId, GET /consents |
optin_links:create | POST /optin-links |
profile:write | PATCH /business-profile |
webhooks:manage | /webhooks, /webhook-deliveries |
templates:manage | Reserved for message templates (coming later) |
Headers#
- Base URL:
https://api.quic.chat/platform/v1. HTTPS only. - Responses carry
QuiC-Request-Id(quote it to support) andQuiC-Version: 2026-10-01. Idempotency-Keyis required onPOST /messagesand honoured on every POST. See idempotency.- Rate-limit headers:
RateLimit-Limit,RateLimit-Remaining, andRetry-Afteron 429.