Qubit API v1

Security

What we never expose, and what we ask of you.

What the platform does to keep an integration safe, and what it asks of you in return.

What you never receive

What we ask

Transport and headers

TLS 1.2 or newer. Every response carries X-Request-ID, a strict Content-Security-Policy, X-Content-Type-Options: nosniff, Referrer-Policy and Strict-Transport-Security. The public API sets no cookies and accepts none: an API key can never be promoted into a session.

Rate limits as a control

Per-application limits (Rate limits) mean a bug that loops cannot spend the business's whole messaging budget in a minute, and the send bucket on top of the request bucket means a loop of reads cannot mask a loop of sends.

Audit

Every credential issued, rotated, revoked or suspended, every scope or channel changed, and every webhook endpoint created or disabled is in the workspace's audit log with who, when and from where. Request logs keep every call your application made - method, path, status, duration, request id - for the business to inspect in the developer portal.

Reporting a vulnerability

If you believe you have found a security issue in the API, write to the address on the business's developer portal page and include a request id where you can. Please do not test against a live workspace's customers.

Base URL https://communication-api.artofluminaire.com Every response carries X-Request-ID; quote it when you write to support.