Authentication
Keep company API keys on the server and separate them from dashboard access.
Every extraction POST and result GET requires a company API key in the X-API-Key header.
X-API-Key: YOUR_SERVER_API_KEY
Accept: application/json
Use HTTPS. Store the key in a server environment variable or secret manager, and load it at runtime. Never put it in browser JavaScript, a mobile application, source control, public URLs or logs. Your users call your backend; your backend calls INE API.
Company access
Several users can submit through the same company integration. Give each business transaction its own Idempotency-Key. The company's monthly quota, two active jobs and ten new jobs per rolling minute are shared across its users and integrations.
Only the company that owns a job can retrieve it. Possessing a request_id alone does not grant access. A result lookup with another company's key returns 404.
Invalid or revoked keys
{
"request_id": "00000000-0000-4000-8000-000000000001",
"error": {
"code": "invalid_api_key",
"message": "Invalid or revoked API key.",
"action": "check_api_key"
}
}
This response uses HTTP 401. Check your backend configuration or contact support for provisioning, rotation or revocation. Share a request identifier when available; never send your secret key in a support message.
The service stores a hash of the API key for authentication. This does not make a leaked key harmless: anyone holding an active key can submit jobs and access that company's unexpired results.
Dashboard access is separate
The private usage dashboard uses a revocable access code and an eight-hour session. Its code is not an OCR API key. Do not paste an API key into the dashboard login. See dashboard usage.