Personal API
Authentication
The token header, account confirmation with the ID and the language of the answers.
Every request carries the token in the Authorization header:
GET /api/v1/vaults HTTP/1.1
Host: wire.ia.br
Authorization: Bearer paper_k3m9x2ab_Q7wLc2…
X-Paper-Account: 3f2a9c…(account ID, 32 characters)
Accept-Language: enAccount confirmation
The X-Paper-Account header is optional and recommended. It carries the ID of the account that owns the token, shown in Settings → Developer and in Settings → Profile.
If the ID doesn't match the token's owner, the request fails with 403, without touching anything. This keeps an agent from using, by mistake, someone else's token left in a history, an old file or the wrong conversation.
AI agents should always send this header.
Language of the answers
Error messages come in the language of Accept-Language: pt-BR (default), en or es. JSON field names don't change.
What's checked on every request
- The token format.
- Whether the token exists, wasn't revoked and hasn't expired (
401if not). - Whether the account exists, isn't banned, has developer mode on and has accepted the current API terms (
403if not). - Whether
X-Paper-Accountmatches the account (403if not). - The per-minute and per-day limits (
429if exceeded). See Limits. - Whether the token has permission for the request's vault, calendar or attachments (
403if missing).
Good practices
- Always use
https://. A request tohttp://is redirected, but the token has already traveled unprotected. - Don't send the token as a URL parameter. It shows up in logs and histories.
- Keep the token out of the code: environment variable, secrets manager or password vault.