Authentication
Public API requests authenticate with a Bearer API key. The key controls the scopes available to the integration.
Required header
Authorization: Bearer <QUICKRCM_API_KEY>
Content-Type: application/jsonAuthentication rules
| Topic | Detail |
|---|---|
| Credential type | Public API requests use a Bearer API key issued for an integration. |
| Header | Authorization: Bearer <QUICKRCM_API_KEY> |
| Scope | Keys may be limited by module, route, action, organization membership, feature flag, or product entitlement. |
| Tenant selection | Tenant selection is handled by the key configuration. Public request payloads should contain endpoint workflow fields, not tenant override fields. |
| Actor attribution | Treat the integration key as the actor until an endpoint documents a stronger external requester or correlation model. |
| Storage | Store keys server-side only. Do not place keys in browser code, mobile apps, logs, screenshots, support tickets, or example fixtures. |
Request handling rules
| Rule | Detail |
|---|---|
| Send exactly one Authorization header. | Multiple credentials, session cookies, or internal HMAC headers are not part of the public API contract. |
| Use least-privilege keys. | Create separate keys for separate partners, services, or environments so scope and rotation are isolated. |
| Rotate on ownership changes. | Rotate keys when staff, vendors, service accounts, deployment targets, or partner access changes. |
| Do not retry auth failures blindly. | Fix the missing, inactive, malformed, expired, or under-scoped key before retrying high-volume requests. |
Common authorization outcomes
| Status | Meaning |
|---|---|
| 401 | Missing, malformed, inactive, or invalid API key. |
| 403 | Valid key, but blocked key configuration, missing scope, disabled feature, or RBAC denial. |
| 404 | Resource is absent or unavailable to the authenticated key. |
| 429 | Rate limit exceeded for the key or endpoint window. |
Key handling
Rotate keys when a partner, vendor, employee, or service owner no longer needs access. Use least-privilege scopes and never share live keys in Slack, tickets, logs, screenshots, or client-side code.
Auth exceptions
The generated OpenAPI baseline has bearer security on 426 of 427 operations. The current exception is GET /api/v1/medical-coding/code-systems. Treat that route as needing security review before using it in generic auth examples.