Skip to content

Developer portal

Authentication & RBAC

Each tenant receives scoped API keys with viewer, operator, or admin roles. Platform admin routes use a separate key.

Last updated: 2026-06-09

Supported headers

  • Authorization: Bearer <key> — preferred for server-side integrations
  • x-api-key: <key> — convenient for tools and proxies
  • ?api_key=<key> — read-only catalog endpoints only
  • X-Request-Id — optional; echoed on every response for support correlation
  • Idempotency-Key — supported on POST /pqc/scan

RBAC roles

  • viewer — read scans, reports, portfolio, analytics; cannot create schedules or modify remediation
  • operator — default for new keys; scans, schedules, remediation writes, integrations
  • admin — audit log, settings, offboarding, billing portal, OIDC config, partner children
Full RBAC matrix →

Examples

Bearer (curl)

curl -X POST "https://api.qtangl.com/pqc/scan" \
  -H "Authorization: Bearer 811f31d4-5b8e-4ed0-a7a2-8176e05eba63" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: scan-$(uuidgen)" \
  -d '{
  "scenarioId": "bank-tls-inventory",
  "useFixture": true
}'

Platform admin key

Routes under /admin/* require QTANGL_ADMIN_API_KEY — not a tenant role. Used for tenant provisioning and key lifecycle. See Admin & key lifecycle.

Dashboard sign-in & team roles

Humans sign in at /dashboard via WorkOS (email magic link or enterprise SSO). First sign-in can self-provision a free Assess workspace with admin role. Tenant admins invite colleagues and assign admin, operator, or viewer under Settings → Team (Monitor tier+ for invites). See Dashboard team & roles.

Enterprise OIDC SSO is configured via PUT /tenant/oidc (admin role). API keys remain required for programmatic access. See Dashboard SSO setup.

Key rotation

  1. Issue a new key via admin API or deployment environment.
  2. Update clients to send the new header value.
  3. Revoke the old key after traffic drains — keys stored as SHA-256 hashes; plaintext shown once.

Public routes

GET /health, GET /pqc/verify/{scanId}, transparency log endpoints, and Readiness Index are public. They use a separate 60 requests per minute per client IP limit — not your API key budget. See Rate limits & quotas. All /tenant/* and mutating /pqc/* routes require a valid tenant key (300/min on writes; reads exempt).