Qonto · Authentication Profile
Qonto Authentication
Authentication
Qonto secures its APIs with apiKey, oauth2, and mtls across 3 declared security schemes, as derived from its OpenAPI definitions.
Business BankingNeobankFintechPaymentsSEPAOpen BankingEUREurope
Methods: apiKey, oauth2, mtls
Schemes: 3
OAuth flows:
API key in:
Security Schemes
secret_key apiKey
· in: header ()
oauth2 oauth2
qsealc mtls
Source
Authentication Profile
generated: '2026-07-17'
method: documented
source: https://docs.qonto.com/get-started/business-api/authentication/api-key
summary:
types:
- apiKey
- oauth2
- mtls
schemes:
- name: secret_key
type: apiKey
in: header
headerName: Authorization
format: '{sign-in}:{secret-key}'
note: >-
Organization sign-in and secret key concatenated with a colon in the
Authorization header. Resembles HTTP Basic authentication but is NOT - the
value is not Base64 encoded. Generated from the Qonto app under Integrations
and Partnerships > API key.
sources:
- https://docs.qonto.com/get-started/business-api/authentication/api-key
- name: oauth2
type: oauth2
flow: authorizationCode
tokenUrl: https://thirdparty.qonto.com/oauth2/token
accessTokenTtlSeconds: 3600
refreshTokenTtlDays: 90
supportsOpenIdConnect: true
note: >-
OAuth 2.0 authorization code flow; recommended for SaaS integrations. Access
token valid 1 hour, refresh token 90 days (offline_access scope), ID token via
openid scope. Client secret must only be used server-side. Per-resource scopes
(e.g. organization.read, payment.write, card.write, sepa_direct_debit.write,
webhook). A User OAuth flow enables access across multiple organizations of the
same user.
sources:
- https://docs.qonto.com/api-reference/business-api/authentication/oauth2/create_tokens
- https://docs.qonto.com/get-started/business-api/authentication/oauth/oauth-flow
- https://docs.qonto.com/get-started/business-api/authentication/oauth/available-scopes
- name: qsealc
type: mtls
standard: PSD2 QSeal certificate (QSealC)
note: >-
Regulated Third-Party Providers (TPPs) identify themselves via a PSD2 QSeal
certificate for open-banking access.
sources:
- https://docs.qonto.com/get-started/business-api/authentication/qsealc
additionalControls:
- name: Strong Customer Authentication (SCA)
applies_to:
- SEPA transfers
- bulk transfers
- international transfers
headers:
- X-Qonto-Sca-Session-Token
- X-Qonto-MFA
- X-Qonto-2fa-Preference
note: >-
PSD2 Strong Customer Authentication is enforced on sensitive money-movement
operations; the client drives an SCA session and supplies the session token /
MFA challenge headers. Trusted beneficiaries (Embed partners only) can bypass
per-transfer SCA.
sources:
- https://docs.qonto.com/api-reference/business-api/authentication/sca/sca-flows
- name: Idempotency
headers:
- X-Qonto-Idempotency-Key
note: Client-generated key to safely retry create requests without duplication.
sources:
- https://docs.qonto.com/get-started/general/idempotent-requests
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/qonto-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.