Authentication

All requests require a Bearer token in the Authorization header.

Authorization: Bearer qs_live_xxxxx
Content-Type: application/json

Keys Are Scoped to One Agency

A key is issued per agency and grants access only to that agency's clients, quote requests, jobs, and results. Requests for a quote request belonging to another agency return 404, not 403 — the API does not confirm the existence of records outside your scope.

ScopeDescription
quotes:readRead quote requests, job status, and results
quotes:writeCreate quote requests and start runs
carriers:readList carriers available to the agency
webhooks:writeRegister and manage webhook endpoints

Storing the Key

Server side only

The API key authenticates as the agency. Keep it in a server-side secret store — a Salesforce Named Credential, an environment variable, or a secrets manager. Never place it in browser JavaScript, a Lightning component, an Apex class body, a public repository, or application logs.

Carrier Credentials Are Separate

Carrier portal logins are not part of API authentication and are never sent through this API. Each agency configures its carrier credentials in the QuoteSweep dashboard, where they are stored in a secrets vault and used by the quoting agents on the agency's behalf.

Two ownership models are supported, configured per agency:

  • Agency-shared — one set of carrier credentials used for all agents, ideally a dedicated CSR account where the carrier permits it.
  • Per-agent — each QuoteSweep user holds their own carrier logins, isolated unless explicitly shared.

Quoting fails at dispatch if credentials for a selected carrier have not been configured. Confirm credential setup before integration testing.

Example Request

curl -X GET https://api.quotesweep.com/v1/carriers \
  -H "Authorization: Bearer qs_live_xxxxx"