Paper documentation
Personal API

Authentication

The token header, account confirmation with the ID and the language of the answers.

Every request carries the token in the Authorization header:

GET /api/v1/vaults HTTP/1.1
Host: wire.ia.br
Authorization: Bearer paper_k3m9x2ab_Q7wLc2…
X-Paper-Account: 3f2a9c…(account ID, 32 characters)
Accept-Language: en

Account confirmation

The X-Paper-Account header is optional and recommended. It carries the ID of the account that owns the token, shown in Settings → Developer and in Settings → Profile.

If the ID doesn't match the token's owner, the request fails with 403, without touching anything. This keeps an agent from using, by mistake, someone else's token left in a history, an old file or the wrong conversation.

AI agents should always send this header.

Language of the answers

Error messages come in the language of Accept-Language: pt-BR (default), en or es. JSON field names don't change.

What's checked on every request

  1. The token format.
  2. Whether the token exists, wasn't revoked and hasn't expired (401 if not).
  3. Whether the account exists, isn't banned, has developer mode on and has accepted the current API terms (403 if not).
  4. Whether X-Paper-Account matches the account (403 if not).
  5. The per-minute and per-day limits (429 if exceeded). See Limits.
  6. Whether the token has permission for the request's vault, calendar or attachments (403 if missing).

Good practices

  • Always use https://. A request to http:// is redirected, but the token has already traveled unprotected.
  • Don't send the token as a URL parameter. It shows up in logs and histories.
  • Keep the token out of the code: environment variable, secrets manager or password vault.

On this page