Authentication

Public API requests authenticate with a Bearer API key. The key controls the scopes available to the integration.

Required header

Authorization: Bearer <QUICKRCM_API_KEY>
Content-Type: application/json

Authentication rules

TopicDetail
Credential typePublic API requests use a Bearer API key issued for an integration.
HeaderAuthorization: Bearer <QUICKRCM_API_KEY>
ScopeKeys may be limited by module, route, action, organization membership, feature flag, or product entitlement.
Tenant selectionTenant selection is handled by the key configuration. Public request payloads should contain endpoint workflow fields, not tenant override fields.
Actor attributionTreat the integration key as the actor until an endpoint documents a stronger external requester or correlation model.
StorageStore keys server-side only. Do not place keys in browser code, mobile apps, logs, screenshots, support tickets, or example fixtures.

Request handling rules

RuleDetail
Send exactly one Authorization header.Multiple credentials, session cookies, or internal HMAC headers are not part of the public API contract.
Use least-privilege keys.Create separate keys for separate partners, services, or environments so scope and rotation are isolated.
Rotate on ownership changes.Rotate keys when staff, vendors, service accounts, deployment targets, or partner access changes.
Do not retry auth failures blindly.Fix the missing, inactive, malformed, expired, or under-scoped key before retrying high-volume requests.

Common authorization outcomes

StatusMeaning
401Missing, malformed, inactive, or invalid API key.
403Valid key, but blocked key configuration, missing scope, disabled feature, or RBAC denial.
404Resource is absent or unavailable to the authenticated key.
429Rate limit exceeded for the key or endpoint window.

Key handling

Rotate keys when a partner, vendor, employee, or service owner no longer needs access. Use least-privilege scopes and never share live keys in Slack, tickets, logs, screenshots, or client-side code.

Auth exceptions

The generated OpenAPI baseline has bearer security on 426 of 427 operations. The current exception is GET /api/v1/medical-coding/code-systems. Treat that route as needing security review before using it in generic auth examples.