Get started

Authentication

Authenticate every request with an X-API-Key header. Create, rotate and revoke keys from the dashboard.

Send your key in the X-API-Key header of every request. Only the health check is public.

http
POST /api/v1/jobs/extract-criteria HTTP/1.1
Host: onlineresumeparser.com
X-API-Key: sk_xxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Content-Type: application/json
  • Authorization: Bearer … and keys in query strings are not accepted.
  • Keys look like sk_ + 6 hex characters + _ + 32 hex characters. A malformed key is rejected as invalid.
  • All keys of an account share its credit balance and work with every API.

Create, name, rotate and revoke keys in Dashboard → API keys.

  • Call HireLayer from your backend. Never ship a key in browser, mobile or desktop code.
  • Read it from an environment variable such as HIRELAYER_API_KEY and keep it out of version control.
  • Use one key per environment or service, so you can revoke one without touching the others.
.env
# .env — server-side only, never commit it
HIRELAYER_API_KEY=sk_xxxxxx_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
StatusBodyCause
401{"error": "Missing API Key"}No X-API-Key header.
401{"error": "Invalid API Key"}Malformed, unknown or revoked key.
403{"error": "Insufficient credits available"}Valid key, but no credit left. See Limits and credits.