Skip to main content
Each call carries the API key of the organization in the Authorization header:

API key

  • The key starts with qx_.
  • The key belongs to one organization. A call reaches only the data of that organization.
  • The QX admin creates the key and delivers the key text through a single-use link. The text appears only once.
  • Keep the key in the secrets manager of your server.
  • Never send the key by email, and never write the key to a log.
  • If the key leaks, ask QX to revoke the key. The next call with the revoked key gets 401.

Refusals

The API checks the key and the organization before each call.

Limits

A paid write is a call that starts a paid service, such as a CNPJ lookup or the reading of a document. These are the paid writes:
  • POST /contacts;
  • POST /collections;
  • POST /documents;
  • PATCH /documents/{id} with file.
  • The day of the daily limit follows the time zone of the organization. The limit resets at midnight.
  • Each 429 response has the Retry-After header, with the seconds to wait.
  • QX adjusts the daily limit of a key when the organization asks.