Skip to main content

Authentication

The public programmatic API uses tenant API keys, not your login JWT. This page covers API keys. Session login is described in Getting started.

Create a key in the app

1

Open API Keys

Go to Settings → API Keys.
2

Create or rotate

Each workspace has one active key for programmatic uploads, balance checks, and top-up. Create a key, or Rotate to invalidate the old one.
3

Copy once

The full sk_live_… secret is shown once. Store it in your secrets manager; the UI only shows a masked prefix afterward.
Rotating or revoking a key immediately breaks integrations still using the old secret. Update clients before or right after rotate.
Keys are also offered during onboarding after signup — save that reveal if you plan to integrate immediately.

Request header

Include the Bearer prefix. The Nest OpenAPI security scheme name is api-key (API key in the Authorization header), which Mintlify’s playground reads from openapi/programmatic.json.

What the API key can do

Upload with an API key

Optional vendorId (query or multipart form field) steers Tier 1 template extraction. Responses are 202 Accepted — extraction is async. The body includes statusUrl (relative path /api/v1/invoices/{id} — prepend the API host). Poll until extraction finishes:
See API overview and the generated playground pages.

Top up with an API key

You can also top up in the app: Settings → Billing. Details: Credits and billing.

Errors