Create an API key
Verify your email, sign in to PaperDrill, and open API keys. Create a separate key for each integration and grant only the permissions it needs. Copy the complete key when it appears. PaperDrill shows it only once.Store the key
Keep the key in a server-side environment variable or secret manager:Send the key
Pass the complete value in thex-api-key header:
Authorization: Bearer, prepend another prefix, or remove the key’s existing pdk_ prefix.
Permissions
Creating and cancelling orders requires a verified account. Read-only order and account endpoints still enforce their listed API-key scope.
Authentication errors
401 AUTHENTICATION_REQUIREDmeans no usable credential was supplied.401 INVALID_API_KEYmeans the key is malformed, revoked, or incorrect.403 FORBIDDENmeans the key lacks the required scope.403 EMAIL_NOT_VERIFIEDmeans the account must be verified before the requested mutation.