> ## Documentation Index
> Fetch the complete documentation index at: https://developers.useqx.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How the API key identifies the organization, and the limits of each key.

Each call carries the API key of the organization in the `Authorization` header:

```text theme={null}
Authorization: Bearer qx_sua_chave
```

## API key

* The key starts with `qx_`.
* The key belongs to one organization. A call reaches only the data of that organization.
* The QX admin creates the key and delivers the key text through a single-use link. The text appears only once.
* Keep the key in the secrets manager of your server.
* Never send the key by email, and never write the key to a log.
* If the key leaks, ask QX to revoke the key. The next call with the revoked key gets `401`.

## Refusals

The API checks the key and the organization before each call.

| Status | `code` | When |
| - | - | - |
| 401 | `unauthorized` | The key is missing, does not exist or is revoked. |
| 402 | `subscription_blocked` | The subscription of the organization is blocked. |
| 403 | `organization_archived` | The organization is archived. |
| 403 | `plan_required` | The free plan does not include the API. |

## Limits

A paid write is a call that starts a paid service, such as a CNPJ lookup or the reading of a document. These are the paid writes:

* `POST /contacts`;
* `POST /collections`;
* `POST /documents`;
* `PATCH /documents/{id}` with `file`.

| Limit | Value | `code` of the `429` |
| - | - | - |
| Calls from one key | 300 per minute | `rate_limited` |
| Paid writes from one key | 30 per minute | `rate_limited` |
| Paid writes from one key | 1,000 per day | `daily_limit_reached` |
| Invalid keys from one IP address | 60 per minute | `too_many_invalid_keys` |

* The day of the daily limit follows the time zone of the organization. The limit resets at midnight.
* Each `429` response has the `Retry-After` header, with the seconds to wait.
* QX adjusts the daily limit of a key when the organization asks.
