invalid_api_key
HTTP 401 · not billed
{ "error": {
"code": "invalid_api_key",
"message": "…",
"docs_url": "https://pdfcraft.dev/errors#invalid_api_key"
} }When you get it
The Authorization header is missing, malformed, or the key has been revoked.
The Authorization header was missing, malformed, or the key behind it has been revoked. The same error is returned for all three on purpose: an attacker learns nothing from the difference between "no such key" and "wrong secret".
How to fix it
- Send Authorization: Bearer sk_live_… — the scheme is required.
- Check the key has not been revoked in the dashboard.
- A closed account returns this too, rather than a distinct code.
Is it billed?
No. A request is billed only when Chromium actually ran. A 401 immediately after a working integration usually means the key was rotated, not that the request changed.
Reproducing it
curl -i -X POST https://api.pdfcraft.dev/v1/render \
-H "Authorization: Bearer $PDFCRAFT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"html":"<h1>hi</h1>"}'The -i matters: Retry-After and X-Renders-Remaining are headers, and a client that only reads the body throws away the two numbers that tell it what to do next.
Every code
| HTTP | Code | Billed? |
|---|---|---|
| 400 | invalid_request | free |
| 401 | invalid_api_key | free |
| 402 | payment_required | free |
| 404 | not_found | free |
| 408 | render_timeout | free |
| 422 | render_failed | billed |
| 429 | rate_limited | free |
| 429 | quota_exceeded | free |
| 429 | demo_busy | free |
| 415 | unsupported_file | free |
| 422 | extraction_failed | free |
| 500 | internal_error | free |