> ## Documentation Index
> Fetch the complete documentation index at: https://quantura.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication and API keys

> Create a scoped Quantura API key, copy it once, and authenticate read-only CSV and forecast integrations safely.

# Authentication and API keys

Quantura API keys use the `qnt_live_` prefix and are sent as bearer credentials:

```http theme={null}
Authorization: Bearer qnt_live_...
```

Never place API keys in query strings, browser storage, client-side bundles, screenshots, analytics events, or logs.

## Get your API key

1. Sign in to Quantura.
2. Open **Account / Developer** from the dashboard, or use the **Manage API keys** action on the developer API page.
3. Choose **Create API key** and give the key a descriptive name.
4. For an integration that only lists and downloads uploaded CSV files, grant `datasets:read`. Add `workspaces:read` when the integration needs to discover shared workspaces.
5. Copy the `qnt_live_...` secret immediately. The plaintext secret is shown only once.
6. Store the key in a server-side secret manager or environment variable such as `QUANTURA_API_KEY`.

The public developer page is available at `/developers/api`. The machine-readable endpoint reference is generated from `/api/openapi.json` and is also used by the Mintlify endpoint reference.

## CSV download quickstart

```bash theme={null}
export QUANTURA_API_KEY="qnt_live_..."

curl -H "Authorization: Bearer $QUANTURA_API_KEY" \
  "https://quantura.studio/api/v1/workspaces"
```

See [Q Search](/docs/q-search) and [Q Download](/docs/q-download) for public market discovery and history.

## Key lifecycle

API keys support a name, scopes, optional expiration, last-used timestamp, replacement, and immediate revocation. The plaintext secret is returned only at creation. Quantura stores a keyed digest and a non-secret prefix for identification.

Replacing a key creates a new secret and revokes the replaced credential. Revoking a key takes effect immediately for future requests.

## Scopes

Use the narrowest scopes required by the integration. Relevant read scopes are:

* `datasets:read` to inspect or download permitted uploaded CSVs and dataset metadata.
* `workspaces:read` to list current workspace access.
* `forecasts:read` to read authorized Quantura Forecast / Q Forecast jobs and results.
* `predictions:read` to read authorized prediction-analysis resources.

Write/compute scopes such as `forecasts:write`, `datasets:write`, or SageMaker execution scopes are **not required** for a CSV retrieval client.

Scopes do not replace workspace authorization. Quantura also evaluates current membership, role, resource ownership, and plan entitlement on every request. A viewer collaborator may read resources that are currently shared with them, but the same key does not gain permission to modify the owner's workspace.

## Recommended secret handling

```python theme={null}
import os

api_key = os.environ["QUANTURA_API_KEY"]
headers = {"Authorization": f"Bearer {api_key}"}
```

Do not commit a real key to Git, paste it into Codex prompts, or place it in public examples. Use a placeholder such as `qnt_live_REPLACE_ME` in documentation and tests.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.