API reference
Account endpoints
Check that a key works and see what it is allowed to do.
Check a key
Returns the key’s name, its scopes, the account it belongs to and its rate limit.
API key required. No scope needed: any valid key may call it. A campaign-scoped key may call it for its own campaign. Plan: Pro, or the Business card plan.
Request
| Header | Required | Value |
|---|---|---|
Authorization | Required | Bearer YOUR_API_KEY. X-API-Key: YOUR_API_KEY is accepted instead. |
No parameters and no body.
Example request
curl "https://api.qrbold.com/api/public/v1/me" \
-H "Authorization: Bearer $QRBOLD_API_KEY"Response
200 The key is valid and the account’s plan includes the REST API.
200 response
{
"object": "api_key_context",
"key": {
"id": "cmf3jz8n10000",
"name": "HR onboarding sync"
},
"scopes": [
{
"scope": "cards:read",
"description": "List and retrieve digital business cards"
},
{
"scope": "cards:write",
"description": "Create, update and delete digital business cards"
}
],
"account": {
"id": "cmf2x9u4w0000",
"email": "you@example.com",
"plan": "pro"
},
"rateLimit": {
"requestsPerMinute": 120
}
}Errors
Every endpoint can also answer 401 invalid_api_key, 403 forbidden, 403 upgrade_required_api, 404 unknown_endpoint, 429 rate limited and 500 internal_error. One failing response is shown below.
401 response
{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "Invalid API key"
}
}Good to know
- Read-only and free of side effects, so it is safe to call from a health check.