Video APIv1 Home OpenAPI spec

Docs › Authentication

Authentication

Every request carries your API key as a bearer token:

Authorization: Bearer vpk_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
  • Your key is issued to you by the service owner. Treat it like a password: anyone who has it can upload videos as you.
  • Each key belongs to one user. You only ever see your own videos; any other video ID answers 404 NOT_FOUND.
  • A missing, unknown or revoked key gets 401 UNAUTHORIZED. Revoked keys stop working within a minute.

Accounts and API keys

Sign up in the web app with your email (a 6-digit code is sent to you). Once signed in, create API keys on the Account page. Each key is shown once; you cannot retrieve it again. API keys can also be created programmatically with POST /account/keys when signed in with a session token. Your account shows your plan, usage this month and API keys.

Keep the key on your server. Don't put it in a web page, a mobile app or a public repository, where anyone can extract it. Call the API from your backend, and hand your users' browsers only the pre-signed upload URLs and download links, which are safe to share and expire on their own. See Uploads from a browser.