Static API keys
Static API keys are the recommended authentication method for server-to-server integrations. They can be generated in the Photo Collect web interface and inherit the permissions of the assigned system user.
API keys and UUID-style user tokens are exactly 36 characters and contain only ASCII letters, digits, or hyphens.
Send the key with either supported header format:
Authorization: Custom <API_KEY>
X-Api-Key: <API_KEY>
The interactive console uses the Authorization form. The key is stored only in a server-side PHP session and is masked in the user interface.
Dynamic user tokens
Use a token only when an integration acts on behalf of a logged-in user, such as an app login.
- Call
POST /tokenwith HTTP Basic authentication. - Use the returned token in the same place as an API key.
- A token expires two weeks after its last use.
- Call
GET /tokento resolve the user, roles, accessible sites, and locale defaults.
Errors
Invalid or missing credentials return HTTP 401 with an error body such as:
{
"error": "Invalid token provided",
"errorcode": "ACCESS_DENIED"
}
Keep keys outside source control, rotate them when exposure is suspected, and never log the full authorization header.