Bearer authentication and token management
Every endpoint in this API reference requires an account API token. Publicly viewable documentation does not make the document-management API anonymous.
Obtain and send a token
Sign in and open Settings → API Tokens. The legacy /user/api-tokens page redirects to this settings tab. Copy the newly issued token into server-side secret storage and send it using the Authorization header:
curl --request POST "https://app.docuwriter.ai/api/user" \
--header "Authorization: Bearer $DOCUWRITER_API_TOKEN" \
--header "Accept: application/json"
POST /api/user returns the authenticated account's basic profile. Use GET /api/user-info when you also need credit and subscription information.
Token handling
Keep tokens out of browser bundles, source control, shared screenshots and URL query strings. Use a separate token for each integration so you can revoke one without interrupting the others. If a token is exposed, revoke it in settings and replace it in your integration.
A token identifies the account; it does not bypass Space permissions, plan restrictions, credits or repository-provider permissions. REST account tokens and MCP OAuth authorization are different integration paths. Follow the MCP connection guide when connecting an AI assistant.
Diagnose a failed request
- 401: verify the token is complete, active and sent with the
Bearerprefix. - 403: authentication may have succeeded, but the account lacks access or the required entitlement. Check the response message.
- 405: verify the method;
/api/useruses POST, while/api/user-infouses GET. - HTML instead of JSON: verify the host, path and
Accept: application/jsonheader.
Start with the read-only account request before troubleshooting a generation or document mutation. Do not include your full token when contacting support.
Updated