Documentation / Authentication

Authentication

Keep company API keys on the server and separate them from dashboard access.

Every extraction POST and result GET requires a company API key in the X-API-Key header.

X-API-Key: YOUR_SERVER_API_KEY
Accept: application/json

Use HTTPS. Store the key in a server environment variable or secret manager, and load it at runtime. Never put it in browser JavaScript, a mobile application, source control, public URLs or logs. Your users call your backend; your backend calls INE API.

Company access

Several users can submit through the same company integration. Give each business transaction its own Idempotency-Key. The company's monthly quota, two active jobs and ten new jobs per rolling minute are shared across its users and integrations.

Only the company that owns a job can retrieve it. Possessing a request_id alone does not grant access. A result lookup with another company's key returns 404.

Invalid or revoked keys

{
  "request_id": "00000000-0000-4000-8000-000000000001",
  "error": {
    "code": "invalid_api_key",
    "message": "Invalid or revoked API key.",
    "action": "check_api_key"
  }
}

This response uses HTTP 401. Check your backend configuration or contact support for provisioning, rotation or revocation. Share a request identifier when available; never send your secret key in a support message.

The service stores a hash of the API key for authentication. This does not make a leaked key harmless: anyone holding an active key can submit jobs and access that company's unexpired results.

Dashboard access is separate

The private usage dashboard uses a revocable access code and an eight-hour session. Its code is not an OCR API key. Do not paste an API key into the dashboard login. See dashboard usage.