Authorization header:
API key
- The key starts with
qx_. - The key belongs to one organization. A call reaches only the data of that organization.
- The QX admin creates the key and delivers the key text through a single-use link. The text appears only once.
- Keep the key in the secrets manager of your server.
- Never send the key by email, and never write the key to a log.
- If the key leaks, ask QX to revoke the key. The next call with the revoked key gets
401.
Refusals
The API checks the key and the organization before each call.Limits
A paid write is a call that starts a paid service, such as a CNPJ lookup or the reading of a document. These are the paid writes:POST /contacts;POST /collections;POST /documents;PATCH /documents/{id}withfile.
- The day of the daily limit follows the time zone of the organization. The limit resets at midnight.
- Each
429response has theRetry-Afterheader, with the seconds to wait. - QX adjusts the daily limit of a key when the organization asks.