Key featuresFeaturesPricingSecurityDocsChangelog
Log inStart for free

Getting Started

  • What is QA Note?
  • Quick Start Guide
  • Install Extension
  • Project Members

Feature Guide

  • Screenshot & Annotation
  • Session Recording
  • Maintenance Reports
  • Issue State Model
  • Multi-issue Windows
  • Storage · DOM Snapshot

Integrations

  • GitHub
  • Commit Keys
  • MCP Server
  • Slack
  • Webhook
  • Vercel
  • Existing Playwright

API Reference

  • Authentication
  • Endpoint Reference
  • Public API v1
  • Error Handling

The issue tracker you use with your AI agent. Your agent fixes; QA Note keeps the record.

Made in Seoul · © 2026 QA Note
ProductKey featuresFeaturesPricingSecurityChangelog
ResourcesDocsMCP guideChrome Extension
CompanyBrandTerms of ServicePrivacy Policy

ffgg|CEO: Songwook Han

Business Registration No.: 746-54-00870[Verify]|E-Commerce License No.: 2024-Seoul Mapo-2178

Address: 5F, 26 World Cup buk-ro 6-gil, Mapo-gu, Seoul, Republic of Korea

Email: support@qanote.app|Hosting Provider: Vercel Inc.

© 2026 QA Note. All rights reserved.

Terms of ServicePrivacy PolicyCookie Policy
  1. Home
  2. /
  3. Docs
  4. /
  5. API Reference

Authentication

API Key issuance and authentication methods

Table of Contents
  • Base URL
  • Issuing an API Key
  • Authorization Header
  • Scopes
  • Rate Limiting

Authentication

The QA Note API uses API Key-based authentication. All API requests require a valid API Key.

Base URL

https://qanote.app

Issuing an API Key

  1. Log in to the QA Note dashboard
  2. Navigate to Organization Settings from the left sidebar
  3. Click the API Keys tab
  4. Click the Create New API Key button
  5. Set a name and permissions (Scopes), then create
  6. Store the generated key in a safe place (it cannot be viewed again)

Authorization Header

Include the API Key in the Authorization header of every API request in Bearer token format.

bash
curl https://qanote.app/api/v1/projects \
  -H "Authorization: Bearer qn_YOUR_API_KEY"

Scopes

You can select the required permissions when creating an API Key. If no scopes are specified, all permissions are granted.

ScopeDescription
issues:readRead issues, comments, logs, and screenshots
issues:writeChange issue status/priority, write comments
projects:readList projects

Rate Limiting

API requests are limited to 60 per minute. Exceeding the limit returns a 429 Too Many Requests response. The limit is enforced per API key or OAuth token, with a secondary per-IP limit to stop credential rotation from bypassing protection.

Request bodies are limited to 64KB for /api/v1 and 256KB for /api/mcp. Larger requests return 413 Payload Too Large.

Previous
Existing Playwright
Next
Endpoint Reference

Table of Contents

  • Base URL
  • Issuing an API Key
  • Authorization Header
  • Scopes
  • Rate Limiting