Authentication
All requests require a Bearer token in the Authorization header.
Authorization: Bearer qs_live_xxxxx
Content-Type: application/jsonKeys Are Scoped to One Agency
A key is issued per agency and grants access only to that agency's clients, quote requests, jobs, and results. Requests for a quote request belonging to another agency return 404, not 403 — the API does not confirm the existence of records outside your scope.
| Scope | Description |
|---|---|
quotes:read | Read quote requests, job status, and results |
quotes:write | Create quote requests and start runs |
carriers:read | List carriers available to the agency |
webhooks:write | Register and manage webhook endpoints |
Storing the Key
Server side only
The API key authenticates as the agency. Keep it in a server-side secret store — a Salesforce Named Credential, an environment variable, or a secrets manager. Never place it in browser JavaScript, a Lightning component, an Apex class body, a public repository, or application logs.
Carrier Credentials Are Separate
Carrier portal logins are not part of API authentication and are never sent through this API. Each agency configures its carrier credentials in the QuoteSweep dashboard, where they are stored in a secrets vault and used by the quoting agents on the agency's behalf.
Two ownership models are supported, configured per agency:
- Agency-shared — one set of carrier credentials used for all agents, ideally a dedicated CSR account where the carrier permits it.
- Per-agent — each QuoteSweep user holds their own carrier logins, isolated unless explicitly shared.
Quoting fails at dispatch if credentials for a selected carrier have not been configured. Confirm credential setup before integration testing.
Example Request
curl -X GET https://api.quotesweep.com/v1/carriers \
-H "Authorization: Bearer qs_live_xxxxx"