Authentication
Quote3D secures API endpoints with API tokens. Start external requests with https://api.quote3d.com/v2 and send the same token either as Authorization: Bearer YOUR_TOKEN_HERE or as X-API-Token: YOUR_TOKEN_HERE.
How Authentication Works
- Register and log in to your Quote3D account.
- Generate an API token from your dashboard under the "Tokens" tab.
- Include the token in your API requests. Authorization: Bearer is supported, and X-API-Token is also accepted:
Authorization: Bearer YOUR_TOKEN_HERE - The server verifies your token and grants access if it is valid and unexpired.
Token Format
Quote3D tokens are bearer-style API credentials. Clients should treat them as opaque secrets and avoid depending on the token's internal structure.
A JWT consists of three parts:
- Header: Specifies the signing algorithm and token type.
- Payload: Contains user data and claims (like user ID, email, and expiration time).
- Signature: Verifies that the token has not been tampered with.
A token may look like this:
<base64url-encoded header>.<base64url-encoded payload>.<base64url-encoded signature>For integrations, the important rule is simple: store the token securely, send it on each request, and avoid parsing or exposing it in client code unless the integration explicitly requires a client-side token.
Example: Using Your Token
Here is how you might use your token with curl. Use one authentication header style consistently:
curl -H "Authorization: Bearer YOUR_TOKEN_HERE" https://api.quote3d.com/v2/userOr in the API playground, paste your token into the authorization modal (lock icon) to authenticate your session. You can also use X-API-Token in custom integrations if that header fits better.
Keep your token secret! Treat it like a password—never share it or expose it in public code repositories.