API key authentication, role-based access control, and per-tier rate limits.
curl https://api.qavcm.com/api/projects \ -H "Authorization: Bearer qavcm_sk_live_…"
qavcm_sk_sandbox_demo_00000000GET /api/projectsGET /api/recommendations/:idGET /api/connectors/carbonmark/market/batchGET /api/coveragePOST /api/recommendationsGET /api/sourcesGET /api/source-runsAll Read Only permissionsPOST /api/source-runsPOST /api/matching/runPOST /api/matching/configAll Analyst permissionsManage API tokensAssign rolesAudit log accessAll Operator permissionsX-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset