Skip to main content
API Documentation

Authentication

OG Fetch uses API keys to authenticate requests. The free Preview endpoint can be called without a key (subject to 150 requests/day per IP). Every other endpoint requires a key.

Getting an API key

Sign up at ogfetch.com/signup to create an account. Your key appears immediately on the Keys page in the dashboard.

Key format

Keys start with a ogf_ prefix, an environment marker (live or test), and an opaque random tail:

ogf_live_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6
ogf_test_abc123def456ghi789jkl012mno345pq

Treat keys as secrets. Anyone with your key can call the API on your account. Rotate immediately if a key is exposed in client code, logs, or version control.

Using a key in requests

Pass the key in the Authorization header as a Bearer token:

curl "https://api.ogfetch.com/extract?url=https://example.com" \
-H "Authorization: Bearer ogf_live_..."

Live vs test keys

ogf_live_* keys count against your billed quota and hit real upstream sites. ogf_test_* keys are free-of-charge but return canned responses for a fixed set of fixture URLs — useful for CI and unit tests.

Rotating a key

From the Keys page, click Regenerate. The old key is invalidated immediately and a new key is issued. Update any deployed services within the rotation window.

Rate limits and quotas

Each plan has per-endpoint monthly quotas (see Rate Limiting). All responses include X-RateLimit-* headers so you can monitor consumption in production.

Errors

Authentication-related responses use these status codes — see the full Errors reference for the complete list:

  • 401 Unauthorized — missing key, or the Authorization header is malformed.
  • 403 Forbidden — key exists but doesn't have access to the requested endpoint or scope.
  • 429 Too Many Requests — quota exceeded for the current billing period.