Skip to main content
Ssnap Docs

API authentication

Authenticate requests to the Ssnap screenshot API with a bearer token or an api_key parameter.

Every request to /api/v1/* must carry a valid API key. Keys are created per team in the dashboard under API keys.

Sending the key

Two equivalent forms are accepted.

Bearer token (preferred)
curl -G https://ssnap.cc/api/v1/screenshot \
  -H "Authorization: Bearer prod_1a2b3c..." \
  --data-urlencode "url=https://example.com"
api_key parameter
curl -G https://ssnap.cc/api/v1/screenshot \
  --data-urlencode "api_key=prod_1a2b3c..." \
  --data-urlencode "url=https://example.com"

The bearer header takes precedence when both are present. Prefer it: query strings end up in browser history, proxy logs and server access logs.

Key format

Keys are a short environment prefix followed by 64 hexadecimal characters:

EnvironmentPrefixExample
Productionprod_prod_9f3c… (64 hex)
Stagingstg_stg_9f3c…
Localdev_dev_9f3c…

Only the SHA-256 hash of a key is stored. The plaintext value is displayed exactly once, at creation.

What a key carries

A key is bound to the team that was active when it was created. That binding determines:

  • the monthly screenshot quota it draws from,
  • the per-minute rate limit applied to it,
  • the team that owns every screenshot it captures.

Keys are throttled individually: two keys on the same team each get the plan's full per-minute allowance, but they share the one monthly quota.

Authentication failures

StatusCodeMeaning
401missing_api_keyNo bearer token and no api_key parameter.
401invalid_api_keyThe key does not match any active record.
403api_key_inactiveThe key exists but has been deactivated.
403api_key_expiredThe key is past its expires_at date.
401 response
{
  "error": "Missing API key",
  "code": "missing_api_key"
}

Never ship a key in client-side code. A leaked key can spend your whole monthly quota. Proxy captures through your own backend, and rotate keys from the dashboard if one escapes.

See API keys for creating, expiring and revoking keys.

Next