API Keys
API keys authenticate your application with Paperful.
You'll need an API key before using the REST API, SDKs, MCP or other programmatic integrations.
Create an API key
Open the API Keys page in the Paperful Console.
Create a new API key and give it a descriptive name, such as:
- Production
- Local development
- CI
- Backend API
Once created, the API key will be displayed. Make sure to copy the key and store it somewhere secure. The API key will not be shown again.
Store your API key
For local development, we recommend storing your key in an environment variable:
PAPERFUL_API_KEY="pf_..."Best practices for API keys
Keep keys server-side
API keys should only be used from trusted environments such as:
- Backend services
- Serverless functions
- Workers
- CLI applications
- CI pipelines
Do not embed a Paperful API key directly in browser or mobile application code.
If your frontend needs to interact with Paperful, send requests through your own backend instead.
Use separate keys
We recommend creating separate API keys for different environments and applications.
For example:
- paperful-api-production
- paperful-api-staging
- paperful-api-ci
This makes it easier to rotate or revoke a key without affecting unrelated systems.
Revoke a key
If a key is no longer needed or may have been exposed, revoke it from the API Keys page in the Console.
Requests using a revoked key will no longer be authenticated.
If you believe a key has been compromised, revoke it and create a replacement.
Test your key
You can verify that your key is working by requesting your usage:
curl https://api.paperful.io/v1/usage \
-H "Authorization: Bearer $PAPERFUL_API_KEY"A successful authenticated request will return data from your Paperful workspace.