Overview
All 9Pic API requests are authenticated with a long-lived API key sent in theX-API-Key header. Keys are scoped to one organisation and validated on every request, along with the calling host and the URL’s org_id / event_id.
Sending the API Key
Add theX-API-Key header to every request:
Creating an API Key
1
Open Developer Zone
Sign in to admin.9pic.ai and open the Developer Zone page from the left sidebar.
2
Create a new token
Click Create Token, then confirm in the dialog. The new key is generated server-side and added to your token list.
3
Copy your token
The full key is displayed only once. Click Copy and store it in your secret manager. If you lose it, you must delete the old token and create a new one.
Each organisation can have up to 10 API tokens. You can deactivate or delete tokens at any time from the Developer Zone page.
Managing Tokens
From the Developer Zone page you can:- Activate / Deactivate a token using the toggle. Deactivated tokens are immediately rejected.
- Delete a token permanently. Any service using that token loses access on the next request.
What Gets Validated
Every API call is checked against three things:
A failure on any of these returns a
403. See Errors for the full list of 403 causes.
Error Responses
See Errors for canonical descriptions and retry guidance.

