التوثيق
ESC
تسجيل الدخول استخدام QuQi
API
Getting started
The QuQi API Authentication
Your account
GET List your websites POST Issue a narrowed key
Channels
GET List channels GET One channel
Posts
POST Plan a post GET List posts GET One post POST Publish a post
Articles
POST Plan an article GET List written articles GET One written article
The calendar
GET The calendar
Pictures
POST Make a picture GET The picture library GET Check a task
Webhooks
POST Add a webhook GET List webhooks DELETE Remove a webhook
Reading finished work
GET Status GET Keywords GET List articles GET One article POST Connect a site POST Disconnect a site
Getting started
Errors

Authentication

One kind of key, what it can reach, and how to say which website you mean.

قراءة 4 دقائق All plans

There is one way in: an API key, sent as a bearer token. No OAuth dance, no session, nothing to refresh.

ابدأ من هنا A key belongs to you, not to one website. It reaches every website you are a member of, which is why most requests have to say which one they mean.

Making a key

1
Open Settings → API Keys
Any website will do — the key is yours, so it does not matter which one you are looking at when you make it.
2
Name it after whatever will hold it
Not after yourself. "n8n production" or "our booking script" is what you will want to read in six months when you are deciding whether it is safe to revoke.
3
Copy the secret straight away
It is shown once and never again. QuQi keeps only a scrambled copy, so nobody — including support — can read it back to you.

A key starts with quqi_ followed by a 40-character secret.

انتبه If you lose the secret you cannot recover it. Make a new key, put it in place, then revoke the old one.

Sending it

CURL
curl https://console.quqi.io/api/v1/channels?website_id=YOUR_WEBSITE_ID \
  -H "Authorization: Bearer quqi_YOUR_KEY"

A request with no bearer token comes back as 401. So does a revoked or expired one — an expired key says so in as many words, because the fix is different.

Saying which website

Send website_id on every request — as a query parameter on a GET, or in the body on a POST. You can find the ids with List your websites.

QuQi never guesses. It will not fall back to whichever website you happen to have open in the console: an unattended script would then post to whichever brand you last clicked on, which is the sort of mistake nobody notices until a customer does.

معلومة مفيدة A key can be narrowed to one website, and then it needs no website_id at all. That is what the WordPress plugin and the Shopify app hold — they get one automatically when you pick a website while connecting.

What a key is allowed to do

A key carries permissions, and it can never do more than you can. If you are an editor on a website, a key you make cannot publish there — the key acts as you, and permissions on top of that only narrow it further.

PERMISSIONWHAT IT COVERSWHO CAN
posts:read and friends Reading posts, articles, the calendar, channels. Anyone on the website
posts:write, articles:write Asking for posts and articles. Editors and up
images:write Making pictures. Editors and up
posts:publish Sending a post to a network. Admins and owners
webhooks:manage Adding and removing webhook endpoints. Admins and owners

A key made before permissions existed can do everything, so nothing you already have in place stopped working.

How often you can call

120 requests a minute and 2,000 an hour, counted against the key rather than your server — so one busy script never spends another's allowance. Every response carries X-RateLimit-Remaining; going over gives you 429 and a Retry-After.

Revoking

Revoke from the same screen you made it on. It stops working on the very next request — there is no grace period, and anything holding it starts failing immediately, which is the point.

معلومة مفيدة Disconnecting inside the plugin or the app is not the same as revoking. Disconnecting only forgets the connection; the key stays valid until you revoke it here.
هل أجابت هذه الصفحة عن سؤالك؟ نعم ليس تمامًا