API Reference
Use the current ZipQuantum HTTP API with the correct credential boundary.
Production base
The API base is https://a.zq.tn/api. The remote MCP endpoint is https://a.zq.tn/mcp.
Credential classes
- Public endpoints: no credential.
- Direct user REST operations:
X-Api-Key. - MCP clients: OAuth 2.1 authorization code flow with PKCE and the
mcpscope. - Internal administration:
X-Api-Secret. - Support widget: optional
X-ZipQuantum-Widget-Key.
Supported account surface
| Method | Path | Credential |
|---|---|---|
| GET, POST | /v1/links | API key or MCP OAuth |
| GET, PATCH, DELETE | /v1/links/{link} | API key or MCP OAuth |
| POST | /v1/links/{link}/qr | API key or MCP OAuth |
| GET | /v1/links/{link}/analytics | Plan analytics |
| GET | /v1/analytics | Plan dashboard analytics |
| GET | /v1/account/usage, /v1/account/capabilities | API key or MCP OAuth |
| GET | /v1/mcp/context | MCP OAuth only |
MCP authentication
A compatible client discovers OAuth metadata, opens the ZipQuantum login and consent screen, and receives resource-bound access and refresh tokens. The plan must enable full_api_access and mcp_access. Users can revoke clients from AI assistant connections.
Machine-readable contract
Use the OpenAPI 3.1 contract, llms.txt, and documentation index.
Official examples
The public ZipQuantum mobile examples repository contains optional platform integrations. The SaaS works without a ZipQuantum mobile app.
Rule
Never expose API keys, OAuth tokens, or internal secrets in public JavaScript, URLs, prompts, logs, or distributed applications.