Changelog

Send your API key in the X-API-Key header

The documented way to authenticate is now an X-API-Key request header, which keeps your key out of URLs and request bodies. The apiKey parameter still works.

ChangedAPI

Authenticate a request by sending your API key in the X-API-Key header:

curl --fail --show-error --output example.pdf --request POST \
  --url https://api.html2pdf.app/v1/generate \
  --header 'Content-Type: application/json' \
  --header 'X-API-Key: <your-api-key>' \
  --data '{ "html": "https://example.com" }'

The documentation and every code example now use the header. A key sent in a header does not end up in the query string of a logged URL, and stays separate from the document options in the request body.

Requests that send the key as the apiKey parameter are still accepted, so existing integrations keep working without a change.

Your API key is private: use it from your server or a trusted job, never from browser JavaScript. See Authentication in the documentation.