Skip to main content
All API requests require a Bearer token in the Authorization header. Tokens are scoped to your team and provide access to all brands within your account.

Get an API token

1

Open API Access

2

Create a new token

Click New API Token and give it a descriptive name, such as analytics-export.
3

Copy and store securely

Your token will be shown only once. Copy it immediately and store it securely.
Never commit tokens to version control or expose them in client-side code. Revoke a compromised token from Team Management > API Access.

Use your token

Include the token in the Authorization header with the Bearer prefix:

Token format

All Qwairy API tokens follow this format:
Example: qw-api-a1b2c3d4e5f6789012345678abcdef01

Authentication errors

Authentication failures return HTTP 401 with a flat body. error is a short status label and message explains the failure:

Synthetic error response

See Error codes for both gateway and resource error shapes.

Security practices

Use environment variables

Store tokens in environment variables, not in code.

Use descriptive names

Name tokens by their purpose for easy management.

Revoke unused tokens

Remove tokens that are no longer attached to an active integration.

Separate integrations

Create different tokens for different integrations.

Manage tokens

Manage API tokens from Team Management > API Access:
  • View tokens: See all active tokens with their last usage date
  • Delete tokens: Revoke access immediately by deleting a token
  • Create new tokens: Generate new tokens as needed