Authentication
When to use this page
Use this page when wiring Quotaflow into an SDK, server, CI job, or agent runtime.
Bearer token
Quotaflow accepts a qf_... API key as a bearer token. The key authenticates the request. Every active key must be attached to an explicit organization, project, subscription, package, or contract billing profile. Removed balance-backed billing contexts are rejected.
Authorization: Bearer qf_your_key_here
A qf_org_billing_... organization billing token is a separate, read-only credential for the organization billing API. It is not an API key: model endpoints reject it, and API keys are not accepted by the organization billing endpoints.
Alternate headers
Some clients cannot set Authorization. Quotaflow also accepts:
x-api-key: qf_your_key_here
or:
x-goog-api-key: qf_your_key_here
Security rules
- Never commit API keys.
- Never place API keys in frontend JavaScript.
- Use different keys per customer, environment, or workload when you need separate permissions, audit trails, or revocation boundaries. Do not assume each key has a separate balance.
- Rotate a key immediately if it appears in logs, screenshots, crash reports, or support tickets.
Common authentication errors
{
"error": "Missing API key",
"message": "Please provide an API key in the x-api-key, x-goog-api-key, or Authorization header"
}
This means no key reached the API.
{
"error": {
"message": "Invalid API key",
"type": "authentication_error"
}
}
This means the key is missing, disabled, expired, deleted, or from a different environment.