AUTHENTICATION

Two authentication methods. Use whichever fits your integration.

Method 1: Supabase JWT (Dashboard Sessions)

Used automatically by the Qntyx dashboards. When you sign in at app.qntyx.io/login, Supabase issues a JWT that all product APIs accept.

Authorization: Bearer eyJhbGciOiJIUzI1NiIs...

JWTs are short-lived (1 hour) and auto-refresh via the Supabase client library. Best for browser-based access.

Method 2: API Key (Developer Integrations)

For server-to-server, CI/CD, and SDK usage. Create API keys from any product dashboard → API Keys → Create Key.

Authorization: Bearer qntyx_veil_a3f7c2e19b4d5f8e1c2a3b4d5e6f7a8b

Key Format

PartExampleDescription
Prefixqntyx_Platform identifier
Productveil_Which product this key authenticates
Secreta3f7c2e1...64 hex characters (256 bits) from the OS CSPRNG

Security

Rate Limits

Each product API allows 60 requests per minute per client IP address, on every plan. Separately, each plan has usage quotas (for example signatures per month or messages per day) that differ by product — see that product's pricing page. Going over either returns 429 or 403.

Error Codes

CodeMeaning
401Missing, expired, or revoked token
403Valid token but feature requires a higher plan
429Rate limit exceeded