Evidence-backed facts
- Qdrant documents vector search with collection data and supports admin, read-only, and granular per-collection API keys. informative
- Read-only or granular keys should constrain query consumers, while filters and indexes determine which payload-backed results are eligible and efficient. informative
- Collection creation, point upsert, payload changes, and deletion require separate write authority and must not be exposed through a query-only connector. informative
- Self-hosted Qdrant is not secure by default; authentication, private network binding, TLS, and audit configuration must be enabled before production exposure. informative