Developer portal
Authentication & RBAC
Each tenant receives scoped API keys with viewer, operator, or admin roles. Platform admin routes use a separate key.
Last updated: 2026-06-09
Supported headers
Authorization: Bearer <key>— preferred for server-side integrationsx-api-key: <key>— convenient for tools and proxies?api_key=<key>— read-only catalog endpoints onlyX-Request-Id— optional; echoed on every response for support correlationIdempotency-Key— supported onPOST /pqc/scan
RBAC roles
- viewer — read scans, reports, portfolio, analytics; cannot create schedules or modify remediation
- operator — default for new keys; scans, schedules, remediation writes, integrations
- admin — audit log, settings, offboarding, billing portal, OIDC config, partner children
Examples
curl -X POST "https://api.qtangl.com/pqc/scan" \
-H "Authorization: Bearer 811f31d4-5b8e-4ed0-a7a2-8176e05eba63" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: scan-$(uuidgen)" \
-d '{
"scenarioId": "bank-tls-inventory",
"useFixture": true
}'Platform admin key
Routes under /admin/* require QTANGL_ADMIN_API_KEY — not a tenant role. Used for tenant provisioning and key lifecycle. See Admin & key lifecycle.
Dashboard sign-in & team roles
Humans sign in at /dashboard via WorkOS (email magic link or enterprise SSO). First sign-in can self-provision a free Assess workspace with admin role. Tenant admins invite colleagues and assign admin, operator, or viewer under Settings → Team (Monitor tier+ for invites). See Dashboard team & roles.
Enterprise OIDC SSO is configured via PUT /tenant/oidc (admin role). API keys remain required for programmatic access. See Dashboard SSO setup.
Key rotation
- Issue a new key via admin API or deployment environment.
- Update clients to send the new header value.
- Revoke the old key after traffic drains — keys stored as SHA-256 hashes; plaintext shown once.
Public routes
GET /health, GET /pqc/verify/{scanId}, transparency log endpoints, and Readiness Index are public. They use a separate 60 requests per minute per client IP limit — not your API key budget. See Rate limits & quotas. All /tenant/* and mutating /pqc/* routes require a valid tenant key (300/min on writes; reads exempt).
Found an issue? Report documentation feedback