Paper documentation
Personal API

API overview

What the personal API does, who it's for and the shortest path to your first request.

The personal API lets a program or an AI agent read and write in one person's notebook, with a token that person created and can revoke at any time. There's no API to read data from other accounts, and no third-party access without a token.

Base: https://wire.ia.br/api/v1
Format: JSON (UTF-8). Files: binary body.
Authentication: Authorization: Bearer paper_…
Error language: Accept-Language: en (or pt-BR, es)

The API field names are in Portuguese (conta, titulo, permissoes…), the same for every language. Error messages follow Accept-Language.

The shortest path

Turn on developer mode in Settings → Developer and accept the API terms. See Developer mode.

Create a token. Choose the type (secure for AI, regular for automations), the vaults and what it can do. See Tokens.

Make your first request:

curl https://wire.ia.br/api/v1/me \
  -H "Authorization: Bearer $PAPER_TOKEN" \
  -H "X-Paper-Account: $PAPER_ACCOUNT" \
  -H "Accept-Language: en"

The response shows the account, the token's permissions and the limits.

What you can do

AreaEndpointsPage
AccountGET /meAuthentication
Vaults and pagesGET /vaults, GET/POST /vaults/{vault}/pages, GET/PATCH/DELETE /vaults/{vault}/pages/{id}Vaults and pages
SearchGET /vaults/{vault}/search?q=Search
FilesPOST /vaults/{vault}/files?name=Attachments
CalendarGET/POST /calendar/events, DELETE /calendar/events/{id}Calendar

Where the data lives

Personal notes aren't stored on the Paper server. They live on the person's device and in their Google Drive. So:

  • Regular token: the server reads and writes in the person's Google Drive at request time, using the connection they allowed for the API. Only vaults synced with Drive show up.
  • Secure token: the server keeps an isolated copy of one vault, created when the person made the token. The AI works on that copy, and the person decides what to bring into the real vault. See Copies for AI.

What no token does

  • Open password-protected pages (423).
  • Read groups, which are end-to-end encrypted.
  • Touch the account, sessions, friendships or settings.

For AI agents

The full documentation map, with rules and endpoints, is at /documentation/agents/raw.json. Before acting, read AI agents.

On this page