Skip to content

Authentication

Developer API endpoints require an API key except:

  • POST /api/dev/paste-lite/create
  • PUT /api/dev/paste-lite/update/:ref
  • DELETE /api/dev/paste-lite/delete/:ref

Quick paste creation may omit the key and use the anonymous rolling 24-hour limit for the request’s source IP. Keyless update and deletion require the private management token returned by creation in the X-Manage-Token header. Supplying an API key uses account ownership and the normal account-based monthly quota.

You can pass an API key in one of two ways:

Terminal window
curl https://api.anonpaste.com/api/dev/pastes/get/aB3xYz \
-H "x-api-key: your_api_key_here"
Terminal window
curl https://api.anonpaste.com/api/dev/pastes/get/aB3xYz \
-H "Authorization: Bearer your_api_key_here"

The SDK always uses x-api-key internally.

StatusReasonDescription
401API key requiredNo key was provided
401Invalid API keyThe key doesn’t match any account
401Management token requiredKeyless Quick paste update/delete omitted X-Manage-Token
429Monthly limit reachedFree quota exhausted and no credits available
  • Never expose your API key in client-side JavaScript or public repositories
  • If a key is compromised, regenerate it from Settings → Developer — the old key is immediately invalidated
  • For server-side applications, store the key in an environment variable:
Terminal window
export ANONPASTE_API_KEY="your_api_key_here"
import { AnonPaste } from 'anonpaste-sdk';
const anonpaste = AnonPaste.init({
apiKey: process.env.ANONPASTE_API_KEY!,
});