Start with a scoped key
Organization administrators can create, rotate, and revoke API keys in Organization → API keys inside DocFila. Select only the scopes your integration needs. A key is displayed once at creation or rotation.
Set a server-side environment variable named DOCFILA_API_KEY, then request your account summary.
curl -sS https://api.docfila.com/v1/account \
-H "X-Api-Key: $DOCFILA_API_KEY"The Firebase Hosting fallback is https://docfila-api.web.app.
X-Api-Key header, never in a URL or browser client. Responses return JSON; authentication and authorization failures use HTTP 401 or 403.What you can build
Routes under /v1 require an API key with the listed scope. Document search, extracted text, text-to-PDF creation, and new-version editing currently use a dedicated document-content host; the OpenAPI specification lists that server for each affected route.
| Capability | Example endpoint | Scope |
|---|---|---|
| Account summary | GET /v1/account | accountRead |
| List and manage documents | GET, POST /v1/documents | documentsRead / documentsWrite |
| Search titles and extracted text | GET /v1/documents/search | documentsRead |
| Read extracted text | GET /v1/documents/{id}/content | documentsRead |
| Create a PDF from text | POST /v1/documents/text | documentsWrite |
| Save an edited PDF as a new version | POST /v1/documents/{id}/versions | documentsWrite |
| List folders | GET /v1/folders | foldersRead |
| Signing and audit | POST /v1/signatures/requests, GET /v1/documents/{id}/audit-events | signaturesWrite / auditRead |
Creating document metadata requires an Idempotency-Key header. New-version editing preserves the original and writes a new PDF; extracted-text edits do not preserve the source layout or non-text elements. For all methods, parameters, and responses, see the OpenAPI specification.
Operational details
Rate limits
Organization API keys default to 600 requests per minute per key. When a limit is reached, the API returns HTTP 429 with a Retry-After header.
Security
Keys are scoped to your organization and can be rotated or revoked. Document endpoints enforce ownership. Use HTTPS and store secrets outside source control.
Availability
Check GET /health for API availability. Upload and signing flows can require additional validation and may fail closed when scanning is unavailable.
DocFila for ChatGPT
DocFila's MCP endpoint is https://api.docfila.com/mcp. ChatGPT account authorization starts and remains on www.docfila.com. The MCP endpoint is live on the branded API domain.
Account connection
Users sign in with DocFila, approve scoped access, and can manage or revoke the connection at www.docfila.com/chatgpt/manage. The integration can search and read extracted document text, create PDFs from text, and save edited text as a new PDF version.
For MCP clients
OAuth discovery is available at /.well-known/oauth-protected-resource/mcp. The MCP route is protected and returns an authorization challenge until a user connects.
Reference and support
Download the OpenAPI 3.0 specification for complete paths, scopes, parameters, and response contracts. For product help, contact support@docfila.com or visit the DocFila support page. Please do not send API keys or sensitive documents by email.