Requests to protected endpoints in the svgdiagram.ai REST API require authentication using an API key passed in the HTTP Authorization header. Public catalog and export options endpoints can be queried without credentials.
API Keys
API keys are formatted with the prefix svg_sk_:
svg_sk_1a2b3c4d5e6f7g8h9i0j...You can generate and manage your API keys in your workspace settings at https://svgdiagram.ai/settings.
Endpoint Access
- Public Catalog Endpoints:
GET /rest/v1/designs,GET /rest/v1/designs/:id,GET /rest/v1/designs/:id/preview.png,GET /rest/v1/export-options, andGET /rest/v1/icons. - Protected Endpoints: Generation creation (
POST /rest/v1/generations), diagram fetching, re-rendering, styling, and file downloads.
Authorization Header
Pass your API key as an HTTP Bearer token in requests to protected endpoints:
Authorization: Bearer svg_sk_your_api_key_hereRequest Example
curl -X POST https://svgdiagram.ai/rest/v1/generations \
-H "Authorization: Bearer svg_sk_your_api_key_here" \
-H "Content-Type: application/json" \
-d '{
"prompt": "Sequence diagram of authentication flow",
"design": "auto"
}'Rate Limits & Errors
API requests are subject to per-minute rate limits configured on your account key. When a request exceeds the allowed threshold, the API responds with a 429 Too Many Requests status code.
If a request to a protected endpoint is missing an Authorization header or presents an invalid API key, the API returns a 401 Unauthorized status code:
{
"error": "Unauthorized",
"code": "unauthorized"
}