Authentication
All API requests require an API key. You can pass it via the X-API-Key header or the Authorization: Bearer header.
Some account endpoints (account info, transactions, usage, payments) also accept a JWT session token from the web app login, useful for Developer Portal access.
Using the X-API-Key header
curl -H "X-API-Key: chu_live_xxxxxxxx" \
https://your-domain.com/api/v1/account
Using Authorization Bearer
curl -H "Authorization: Bearer chu_live_xxxxxxxx" \
https://your-domain.com/api/v1/account
Creating an API key
- Log in to the PROOF web app
- Go to Developer Portal (
/developer) - Click Create Key
- Enter a name (e.g., "production", "staging")
- Copy the full key value — it is only shown once
You can also create keys via the API:
curl -X POST https://your-domain.com/api/v1/keys \
-H "Authorization: Bearer <your-jwt-token>" \
-H "Content-Type: application/json" \
-d '{"name": "production", "scopes": ["jobs:read", "jobs:write"]}'
caution
Store your API key securely. Never commit it to source control or expose it in client-side code.
API key scopes
| Scope | Description |
|---|---|
jobs:read | Read job status and list jobs |
jobs:write | Upload, confirm, and convert jobs |
Rate limits
- Default: 60 requests per minute per API key
- Concurrent jobs: up to 5 per account (admin-configurable)
- Daily credit quota: optional per key
When exceeded, the API returns 429 Too Many Requests with a Retry-After header.