Skip to content

API Reference

This page lists only public, live-verifiable API surfaces. Programmatic assessment execution, report retrieval, webhooks, and enterprise integrations are governed routes provisioned after scope approval.

Base URL

https://api.qtonicquantum.com

Authentication

The public status and configuration endpoints below do not require a token. Governed assessment APIs require enterprise onboarding and scoped credentials before any route details are issued.

No public self-serve scan API is advertised.

Access Boundary

QScout public intake is fulfilled by request after scope review. Raw findings, requester artifact downloads, signed reports, and automated execution APIs are not exposed as anonymous public routes.

Verified Public Endpoints

GET/health

QScout API edge health. Returns service status for public uptime monitoring.

GET/version

Runtime version, deployed backend Git SHA, and release metadata.

GET/public/config

Public QScout capability and requester-access policy configuration.

GET/public/scan-canary

Operator runtime canary signal. This is not a public live-scan product API.

Enterprise Integration

SIEM/SOAR integrations, webhooks, evidence export, and custom API access are scoped during enterprise onboarding. Route details are provided only after authorization, tenancy, and delivery controls are established.