Skip to main content

API Key Authentication

All Snipp API endpoints require authentication. Include your API key in the api-key header with every request.

Where to Find Your API Key

  1. Sign in to your account.
  2. Go to Settings.
  3. Copy your API key from the API section.

Examples

API Key Permissions

Every key can upload. Reaching the uploads already in your gallery is a separate permission, off by default: Without gallery access, GET /uploads, PATCH /editUpload, POST /appendUpload and DELETE /deleteUpload return 403. POST /upload is unaffected. You can check whether gallery access is enabled by calling GET /users/@me and reviewing the keyHasUploadsAccess field. The field name is historical and reports gallery access.

Team Access Keys

Teams (an Ultra feature) each have a dedicated access key. A team key works exactly like a personal API key (pass it in the api-key header), but uploads made with it go to the team’s shared gallery instead of a personal account.
Key differences when uploading with a team key:
  • Files are stored in the team gallery, not a personal gallery.
  • Uploads count against the team’s weekly quota, never a member’s personal quota.
  • Team-key uploads are always created private, regardless of the post-privacy header, and their privacy cannot be changed afterward. Team posts are never unlisted or public.
  • Only the team owner can regenerate or delete the key, from the team’s settings page.
  • If the team’s subscription lapses, uploads with the key return 403. Reading, editing, and deleting existing team posts keep working.
The same key also works on the Relay API, passed in its relay-key header, on /upload, /appendUpload, /editUpload, and /deleteUpload. Anyone who holds a team key can upload with it, so treat it like any other credential and share it only with trusted team members.

Security Best Practices

  • Never expose your API key in client-side code, public repositories, or shared documents.
  • Use environment variables in production (for example, process.env.SNIPP_API_KEY).
  • Rotate your key immediately if you suspect it has been compromised. You can regenerate it from your account settings.
  • Limit upload access if your integration only needs read access.

Error Responses

All errors return a JSON object with an error field describing the issue.