Documentation

Authentication

API keys, headers and good practices.

Every request to /v1 and to the MCP server is authenticated with an API key of your workspace.

curl https://pixamake.ai/v1/account -H "Authorization: Bearer pxm_live_..."

The X-API-Key: pxm_live_... header is also accepted.

Keys

  • Create and revoke keys in API and webhooks. A key gives full access to the workspace: its credits, videos and results.
  • Only a hash of the key is stored. If you lose a key, revoke it and create a new one.
  • Revoking a key takes effect immediately.
  • API access requires the Growth or Scale plan. With another plan, requests return 403 plan_required (except GET /v1/account and GET /v1/estimate).

Good practices

  • Keep keys on the server side, never in a browser or mobile app.
  • Use one key per integration (production server, staging, agent) so you can revoke one without touching the others.
  • Never print keys in logs, tickets or prompts shared with other people.

Errors

Status Code Meaning
401 invalid_api_key Missing, unknown or revoked key
403 plan_required The workspace plan does not include the API