Firm administrators can create API keys to connect custom dashboards, AI assistants, and firm-facing tools directly to Quilia. You can also set up webhooks to receive real-time updates when events happen in your firm.
Managing API Keys
Open Settings → Integrations and select API. Only firm administrators can access this page and manage keys.
Create an API key
- Select Create Key.
- Give the key a clear Name (for example, "Custom Reporting Dashboard" or "Firm Portal").
- Select Create.
- Copy the key immediately and store it securely. You will not be able to see the full key again.
(Note: Never share API keys in chat or email, and never include them in screenshots.)
Revoke an API key
If a key is compromised or no longer needed, select Revoke next to it in the keys table. Any system using that key will lose access immediately.
Webhooks
Webhooks send real-time data to your firm's servers when specific events occur in Quilia.
To configure a new webhook:
- Choose the Event you want to listen for.
- Enter your server's Endpoint URL.
- Set the number of Retry Attempts in case your server is temporarily unreachable.
- Provide a Shared Secret. Quilia uses this to sign the payloads it sends so your server can verify the request is genuine.
Verifying webhook signatures
When Quilia sends a webhook event, it includes a signature header so you can verify the request is genuine. To verify the event:
- Extract the raw request body.
- Compute an HMAC SHA-256 digest of the raw request body using your Shared Secret.
- Compare your computed digest to the signature provided in the header. If they match, the request came from Quilia and has not been altered.
Custom API Integrations
For full API documentation, visit the public API reference.
If you are setting up an AI assistant (like Claude Desktop or Cursor), you do not need to create API keys manually. Follow the Connect your AI assistant guide to use the one-click sign-in flow.