Docs › Authentication
Authentication
Every request carries your API key as a bearer token:
Authorization: Bearer vpk_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
- Your key is issued to you by the service owner. Treat it like a password: anyone who has it can upload videos as you.
- Each key belongs to one user. You only ever see your own videos; any other video ID answers
404 NOT_FOUND. - A missing, unknown or revoked key gets
401 UNAUTHORIZED. Revoked keys stop working within a minute.
Accounts and API keys
Sign up in the web app with your email (a 6-digit code is sent to you). Once signed in, create API keys on the Account page. Each key is shown once; you cannot retrieve it again. API keys can also be created programmatically with POST /account/keys when signed in with a session token. Your account shows your plan, usage this month and API keys.
Keep the key on your server. Don't put it in a web page, a mobile app or a public repository, where anyone can extract it. Call the API from your backend, and hand your users' browsers only the pre-signed upload URLs and download links, which are safe to share and expire on their own. See Uploads from a browser.