eCom Learning Solutions / Developer toolsOpen source
Documentation/Security/API keys and authentication
05 / ACCESS

Authentication & browser calls

Check GET /api/v1/security for this deployment's key requirement, body limit, output limit, and rendering timeout. Preset catalog reads, preset detail pages, and preset example downloads always require an X-Api-Key header. PDF POST endpoints require that header when the host enables authentication. The Studio validates the same header before loading templates. Never put keys in a URL.

cURL · authenticated request
curl --fail-with-body '__API_ORIGIN__/api/v1/pdfs/custom-template' \
  -H 'X-Api-Key: YOUR_KEY' \
  -H 'Content-Type: application/json' \
  --data '{"template":{"title":"Example","pages":[{"layout":"flow","blocks":[{"type":"paragraph","text":"Your content."}]}]},"labels":{},"data":{}}' \
  --output example.pdf

Development and production settings require an API key for PDF calls. Studio always requires a valid configured key, even when anonymous generation is enabled. General guides and the deployed source download remain accessible; preset catalog and documentation details require a valid X-Api-Key. Browser workspaces hold a key only in page memory, do not save it to storage, and clear it when leaving the page.

CORS allows all origins by default, without cookies. Hosts can configure an allowlist or disable it. See CSP, CORS & response headers for configuration. Server-to-server HTTP calls do not need CORS.