Getting Your API Key
- Log in to your anyformat account.
- Open the API Key page, generate a key, and copy it. The page shows a key once.
Authentication Method
Use your API key in theAuthorization header with Bearer format:
Using Your API Key
Send your API key in the headers of every request:The API accepts the
Authorization header in any casing, such as authorization or AUTHORIZATION. The HTTP specification makes header names case-insensitive.Verifying a Key
CallGET /key-check/ to confirm a key is active before your first real request. On success it returns 200 with the owning organization. Otherwise it returns the standard 401 error envelope, with error_code MISSING_API_KEY or INVALID_API_KEY. The call bills nothing and creates no run.
API Key Scoping
Each API key belongs to one organization. Every request made with that key operates inside that organization’s data, so it reaches only that organization’s workflows, document packets and runs.- A user who belongs to several organizations needs one API key per organization.
- Generating a new API key revokes the previous key for the same organization.
- An API key grants the same access level as the user who created it. Keys carry no granular scopes and no permission restrictions.
API keys are managed in the anyformat platform. The API does not expose key management endpoints.
Public Endpoints
These endpoints need no API key:/, the API root/health/, the health check/schema/, the OpenAPI schema/docs/, the Swagger UI documentation
Revoking a Key
Generate a new key to automatically revoke the old one.
Security Best Practices
- Never share your API key. Treat it like a password.
- Rotate keys on a schedule. Generate a new key regularly.
- Use environment variables. Store keys in the environment in production.
- Monitor key usage. Watch your account for suspicious activity.
- Never expose a key in client-side code. Use an API key server-side only.
If you suspect a key is compromised, open the API Key page at once and generate a new one.

