API overview

Create an API key, authenticate to the REST API, and learn the base URL, errors, pagination and rate limits. Full endpoint reference lives at /api/v1/docs.

JM
James Morton
Written By James MortonLast updated about 2 hours ago

The REST API lets you build integrations and automate work across feedback, changelog, the help center, support conversations and tickets, and your status page. This article covers authentication, the base URL, errors, pagination and rate limits. For every endpoint and schema, use your workspace's API reference at /api/v1/docs.

Create an API key

  1. Go to Admin > Settings > Developers, on the Keys tab.
  2. Click Create API key.
  3. Give it a Name that says what uses it (for example "Data warehouse sync").
  4. Under Access, choose Read, Read and write, or Write for each area: Feedback, Changelog, Help Center and Conversations. Give the key only what it needs.
  5. Click Create API key and copy the key. It starts with qb_ and is shown only once.

A key can do what its access allows, limited by the permissions of the teammate who created it. Keys are created by teammates whose role can manage API keys (Owner and Admin by default). From the list you can Rotate key (the old key stops working immediately) or Revoke key.

The same access levels are used by the MCP server, so one key works for both.

Authenticate

Send the key as a Bearer token in the Authorization header:

curl https://feedback.example.com/api/v1/posts \
  -H "Authorization: Bearer qb_your_api_key"

Base URL

https://<your workspace domain>/api/v1

The Keys tab shows your exact base URL. Self-hosted installs use their own hostname.

Full endpoint reference

Every workspace serves an interactive API reference at /api/v1/docs (for example https://feedback.example.com/api/v1/docs). It lists every endpoint with request and response schemas, and always matches the version you're running.

The API covers, among others: posts, comments, boards, statuses, tags, roadmaps, changelog, help center articles and categories, users and companies, segments, webhooks, files, conversations, tickets and the status page.

Errors

Errors return an HTTP status code and a JSON body:

{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Webhook URL is required",
    "details": { "field": "url" }
  }
}

Status

Code

Meaning

400

BAD_REQUEST or VALIDATION_ERROR

Malformed or invalid request

401

UNAUTHORIZED

Missing or invalid API key

403

FORBIDDEN

The key lacks the required access or permission

404

NOT_FOUND (or a resource-specific code)

The resource doesn't exist

409

CONFLICT

Duplicate slug, key or name

429

RATE_LIMITED

Too many requests; see the Retry-After header

500

INTERNAL_ERROR

Unexpected server error

Pagination

List endpoints return data plus a meta.pagination object:

{
  "data": [],
  "meta": {
    "pagination": { "cursor": "eyJvZmZzZXQiOjIwfQ", "hasMore": true }
  }
}

Pass the returned cursor back as ?cursor=... to get the next page. Treat cursors as opaque. Use ?limit= to set the page size (default 20, maximum 100).

Rate limits

Requests are limited per client IP address in one-minute windows. Self-hosted installs allow 100 requests per minute by default. On Quackback Cloud, the limit depends on your plan. Going over returns 429 with a Retry-After header.

Get notified instead of polling

Use webhooks to receive events as they happen instead of polling the API.

Was this helpful?

Your feedback shapes what we write next.