Photo Collect API
Photo Collect ↗

Static API keys

Static API keys are the recommended authentication method for server-to-server integrations. They can be generated in the Photo Collect web interface and inherit the permissions of the assigned system user.

API keys and UUID-style user tokens are exactly 36 characters and contain only ASCII letters, digits, or hyphens.

Send the key with either supported header format:

Authorization: Custom <API_KEY>
X-Api-Key: <API_KEY>

The interactive console uses the Authorization form. The key is stored only in a server-side PHP session and is masked in the user interface.

Dynamic user tokens

Use a token only when an integration acts on behalf of a logged-in user, such as an app login.

  1. Call POST /token with HTTP Basic authentication.
  2. Use the returned token in the same place as an API key.
  3. A token expires two weeks after its last use.
  4. Call GET /token to resolve the user, roles, accessible sites, and locale defaults.

Errors

Invalid or missing credentials return HTTP 401 with an error body such as:

{
  "error": "Invalid token provided",
  "errorcode": "ACCESS_DENIED"
}

Keep keys outside source control, rotate them when exposure is suspected, and never log the full authorization header.

⌁

Connect your API

Credentials are kept in this session only.