Authentication & browser calls
Check GET /api/v1/security for this deployment's key requirement, body limit, output limit, and rendering timeout. Preset catalog reads, preset detail pages, and preset example downloads always require an X-Api-Key header. PDF POST endpoints require that header when the host enables authentication. The Studio validates the same header before loading templates. Never put keys in a URL.
curl --fail-with-body '__API_ORIGIN__/api/v1/pdfs/custom-template' \
-H 'X-Api-Key: YOUR_KEY' \
-H 'Content-Type: application/json' \
--data '{"template":{"title":"Example","pages":[{"layout":"flow","blocks":[{"type":"paragraph","text":"Your content."}]}]},"labels":{},"data":{}}' \
--output example.pdfDevelopment and production settings require an API key for PDF calls. Studio always requires a valid configured key, even when anonymous generation is enabled. General guides and the deployed source download remain accessible; preset catalog and documentation details require a valid X-Api-Key. Browser workspaces hold a key only in page memory, do not save it to storage, and clear it when leaving the page.
CORS allows all origins by default, without cookies. Hosts can configure an allowlist or disable it. See CSP, CORS & response headers for configuration. Server-to-server HTTP calls do not need CORS.