Qonto · Authentication Profile

Qonto Authentication

Authentication

Qonto secures its APIs with apiKey, oauth2, and mtls across 3 declared security schemes, as derived from its OpenAPI definitions.

Business BankingNeobankFintechPaymentsSEPAOpen BankingEUREurope
Methods: apiKey, oauth2, mtls Schemes: 3 OAuth flows: API key in:

Security Schemes

secret_key apiKey
· in: header ()
oauth2 oauth2
qsealc mtls

Source

Authentication Profile

Raw ↑
generated: '2026-07-17'
method: documented
source: https://docs.qonto.com/get-started/business-api/authentication/api-key
summary:
  types:
  - apiKey
  - oauth2
  - mtls
schemes:
- name: secret_key
  type: apiKey
  in: header
  headerName: Authorization
  format: '{sign-in}:{secret-key}'
  note: >-
    Organization sign-in and secret key concatenated with a colon in the
    Authorization header. Resembles HTTP Basic authentication but is NOT - the
    value is not Base64 encoded. Generated from the Qonto app under Integrations
    and Partnerships > API key.
  sources:
  - https://docs.qonto.com/get-started/business-api/authentication/api-key
- name: oauth2
  type: oauth2
  flow: authorizationCode
  tokenUrl: https://thirdparty.qonto.com/oauth2/token
  accessTokenTtlSeconds: 3600
  refreshTokenTtlDays: 90
  supportsOpenIdConnect: true
  note: >-
    OAuth 2.0 authorization code flow; recommended for SaaS integrations. Access
    token valid 1 hour, refresh token 90 days (offline_access scope), ID token via
    openid scope. Client secret must only be used server-side. Per-resource scopes
    (e.g. organization.read, payment.write, card.write, sepa_direct_debit.write,
    webhook). A User OAuth flow enables access across multiple organizations of the
    same user.
  sources:
  - https://docs.qonto.com/api-reference/business-api/authentication/oauth2/create_tokens
  - https://docs.qonto.com/get-started/business-api/authentication/oauth/oauth-flow
  - https://docs.qonto.com/get-started/business-api/authentication/oauth/available-scopes
- name: qsealc
  type: mtls
  standard: PSD2 QSeal certificate (QSealC)
  note: >-
    Regulated Third-Party Providers (TPPs) identify themselves via a PSD2 QSeal
    certificate for open-banking access.
  sources:
  - https://docs.qonto.com/get-started/business-api/authentication/qsealc
additionalControls:
- name: Strong Customer Authentication (SCA)
  applies_to:
  - SEPA transfers
  - bulk transfers
  - international transfers
  headers:
  - X-Qonto-Sca-Session-Token
  - X-Qonto-MFA
  - X-Qonto-2fa-Preference
  note: >-
    PSD2 Strong Customer Authentication is enforced on sensitive money-movement
    operations; the client drives an SCA session and supplies the session token /
    MFA challenge headers. Trusted beneficiaries (Embed partners only) can bypass
    per-transfer SCA.
  sources:
  - https://docs.qonto.com/api-reference/business-api/authentication/sca/sca-flows
- name: Idempotency
  headers:
  - X-Qonto-Idempotency-Key
  note: Client-generated key to safely retry create requests without duplication.
  sources:
  - https://docs.qonto.com/get-started/general/idempotent-requests

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/qonto-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.