Skip to main content
Programmable access to protected PaperDrill endpoints uses scoped API keys. Public market-data endpoints do not require authentication.

Create an API key

Verify your email, sign in to PaperDrill, and open API keys. Create a separate key for each integration and grant only the permissions it needs. Copy the complete key when it appears. PaperDrill shows it only once.

Store the key

Keep the key in a server-side environment variable or secret manager:
Never commit the value to source control or embed it in browser or mobile code. Revoke and replace a key immediately if it may have been exposed.

Send the key

Pass the complete value in the x-api-key header:
Do not use Authorization: Bearer, prepend another prefix, or remove the key’s existing pdk_ prefix.

Permissions

Creating and cancelling orders requires a verified account. Read-only order and account endpoints still enforce their listed API-key scope.

Authentication errors

  • 401 AUTHENTICATION_REQUIRED means no usable credential was supplied.
  • 401 INVALID_API_KEY means the key is malformed, revoked, or incorrect.
  • 403 FORBIDDEN means the key lacks the required scope.
  • 403 EMAIL_NOT_VERIFIED means the account must be verified before the requested mutation.
See Errors and rate limits for the shared error envelope and retry guidance.