API Key Authentication
All Snipp API endpoints require authentication. Include your API key in theapi-key header with every request.
Where to Find Your API Key
- Sign in to your account.
- Go to Settings.
- Copy your API key from the API section.
Examples
API Key Permissions
Every key can upload. Reaching the uploads already in your gallery is a separate permission, off by default:
Without gallery access,
GET /uploads, PATCH /editUpload, POST /appendUpload and DELETE /deleteUpload return 403. POST /upload is unaffected.
You can check whether gallery access is enabled by calling GET /users/@me and reviewing the keyHasUploadsAccess field. The field name is historical and reports gallery access.
Team Access Keys
Teams (an Ultra feature) each have a dedicated access key. A team key works exactly like a personal API key (pass it in theapi-key header), but uploads made with it go to the team’s shared gallery instead of a personal account.
- Files are stored in the team gallery, not a personal gallery.
- Uploads count against the team’s weekly quota, never a member’s personal quota.
- Team-key uploads are always created private, regardless of the
post-privacyheader, and their privacy cannot be changed afterward. Team posts are never unlisted or public. - Only the team owner can regenerate or delete the key, from the team’s settings page.
- If the team’s subscription lapses, uploads with the key return
403. Reading, editing, and deleting existing team posts keep working.
relay-key header, on /upload, /appendUpload, /editUpload, and /deleteUpload.
Anyone who holds a team key can upload with it, so treat it like any other credential and share it only with trusted team members.
Security Best Practices
- Never expose your API key in client-side code, public repositories, or shared documents.
- Use environment variables in production (for example,
process.env.SNIPP_API_KEY). - Rotate your key immediately if you suspect it has been compromised. You can regenerate it from your account settings.
- Limit upload access if your integration only needs read access.
Error Responses
All errors return a JSON object with an
error field describing the issue.