Authentication
The public programmatic API uses tenant API keys, not your login JWT.
This page covers API keys. Session login is described in Getting started.
Create a key in the app
1
Open API Keys
Go to Settings → API Keys.
2
Create or rotate
Each workspace has one active key for programmatic uploads, balance checks, and top-up.
Create a key, or Rotate to invalidate the old one.
3
Copy once
The full
sk_live_… secret is shown once. Store it in your secrets manager; the UI only shows a masked prefix afterward.Request header
Bearer prefix. The Nest OpenAPI security scheme name is api-key (API key in the Authorization header), which Mintlify’s playground reads from openapi/programmatic.json.
What the API key can do
Upload with an API key
Optional
vendorId (query or multipart form field) steers Tier 1 template extraction. Responses are 202 Accepted — extraction is async. The body includes statusUrl (relative path /api/v1/invoices/{id} — prepend the API host).
Poll until extraction finishes:
See API overview and the generated playground pages.

