Qualia · Authentication Profile

Qualia Title Authentication

Authentication

Qualia secures its APIs with http across 1 declared security scheme, as derived from its OpenAPI definitions.

Title InsuranceEscrowReal EstateClosingSettlementPropTechGraphQL
Methods: http Schemes: 1 OAuth flows: API key in:

Security Schemes

basicAuth http
scheme: basic · in: header ()

Source

Authentication Profile

qualia-title-authentication.yml Raw ↑
generated: '2026-09-16'
method: searched
source: https://www.qualia.com/qualia-api/
docs: https://www.qualia.com/qualia-api/
provider: Qualia
providerId: qualia-title
note: >-
  No OpenAPI or public GraphQL schema exists to derive security schemes from
  (derive-authentication.py found none). This profile is taken from Qualia's
  public API page, which states "Users are authenticated via a basic HTTP
  authentication framework to identify the organization calling Qualia", and is
  corroborated by anonymous probes of the live endpoint recorded under
  x-evidence. Credentials are issued per organization through Qualia's gated
  onboarding; no credential format or sandbox key prefix is published.
summary:
  types:
  - http
  http_schemes:
  - basic
  api_key_in: []
  oauth2_flows: []
schemes:
- name: basicAuth
  type: http
  scheme: basic
  in: header
  header: Authorization
  identifies: calling organization
  sources:
  - https://www.qualia.com/qualia-api/
authorization:
  model: capability gates + authorized organizations
  capability_gates: >-
    The Qualia API is organized by capability gates, which provide access to
    calls around an objective; customers purchase the capabilities they need.
  authorized_organizations: >-
    Granular controls to grant (or revoke) API access to owned or partner
    organizations to retrieve data on behalf of the end consumer.
  source: https://www.qualia.com/qualia-api/
oauth2: false
openid_connect: false
scopes: none published (access is scoped by capability gates, not OAuth scopes)
x-evidence:
  endpoint: https://api.qualia.com/graphql
  fetched: '2026-09-16'
  probes:
  - request: POST without Authorization header
    http_status: 401
    body: '{"errors":[{"message":"Authorization header is missing","extensions":{"code":"UNAUTHORIZED"}}]}'
  - request: POST with Authorization Bearer <token>
    http_status: 401
    body: '{"errors":[{"message":"Authorization header is not properly formatted","extensions":{"code":"UNAUTHORIZED"}}]}'
  - request: POST with Authorization Basic <invalid credentials>
    http_status: 403
    body: '{"errors":[{"message":"User is not authenticated","extensions":{"code":"FORBIDDEN"}}]}'
  interpretation: >-
    A Bearer header is rejected as malformed while a Basic header is parsed and
    then rejected on credentials, confirming HTTP Basic is the accepted scheme.
  well_known:
  - url: https://api.qualia.com/.well-known/oauth-authorization-server
    http_status: 404
  - url: https://api.qualia.com/.well-known/oauth-protected-resource
    http_status: 404
  - url: https://api.qualia.com/.well-known/openid-configuration
    http_status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/qualia-title-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.