Bearer authentication and token management

Every endpoint in this API reference requires an account API token. Publicly viewable documentation does not make the document-management API anonymous.

Obtain and send a token

Sign in and open Settings → API Tokens. The legacy /user/api-tokens page redirects to this settings tab. Copy the newly issued token into server-side secret storage and send it using the Authorization header:

curl --request POST "https://app.docuwriter.ai/api/user" \
  --header "Authorization: Bearer $DOCUWRITER_API_TOKEN" \
  --header "Accept: application/json"

POST /api/user returns the authenticated account's basic profile. Use GET /api/user-info when you also need credit and subscription information.

Token handling

Keep tokens out of browser bundles, source control, shared screenshots and URL query strings. Use a separate token for each integration so you can revoke one without interrupting the others. If a token is exposed, revoke it in settings and replace it in your integration.

A token identifies the account; it does not bypass Space permissions, plan restrictions, credits or repository-provider permissions. REST account tokens and MCP OAuth authorization are different integration paths. Follow the MCP connection guide when connecting an AI assistant.

Diagnose a failed request

  • 401: verify the token is complete, active and sent with the Bearer prefix.
  • 403: authentication may have succeeded, but the account lacks access or the required entitlement. Check the response message.
  • 405: verify the method; /api/user uses POST, while /api/user-info uses GET.
  • HTML instead of JSON: verify the host, path and Accept: application/json header.

Start with the read-only account request before troubleshooting a generation or document mutation. Do not include your full token when contacting support.

Updated