Get started
Authentication
Authenticate every request with an X-API-Key header. Create, rotate and revoke keys from the dashboard.
Send your key in the X-API-Key header of every request. Only the health check is public.
POST /api/v1/jobs/extract-criteria HTTP/1.1
Host: onlineresumeparser.com
X-API-Key: sk_xxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Content-Type: application/jsonAuthorization: Bearer …and keys in query strings are not accepted.- Keys look like
sk_+ 6 hex characters +_+ 32 hex characters. A malformed key is rejected as invalid. - All keys of an account share its credit balance and work with every API.
Create, name, rotate and revoke keys in Dashboard → API keys.
- Call HireLayer from your backend. Never ship a key in browser, mobile or desktop code.
- Read it from an environment variable such as
HIRELAYER_API_KEYand keep it out of version control. - Use one key per environment or service, so you can revoke one without touching the others.
# .env — server-side only, never commit it
HIRELAYER_API_KEY=sk_xxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx| Status | Body | Cause |
|---|---|---|
401 | {"error": "Missing API Key"} | No X-API-Key header. |
401 | {"error": "Invalid API Key"} | Malformed, unknown or revoked key. |
403 | {"error": "Insufficient credits available"} | Valid key, but no credit left. See Limits and credits. |