Authentication
OG Fetch uses API keys to authenticate requests. The free Preview endpoint can be called without a key (subject to 150 requests/day per IP). Every other endpoint requires a key.
Getting an API key
Sign up at ogfetch.com/signup to create an account. Your key appears immediately on the Keys page in the dashboard.
Key format
Keys start with a ogf_ prefix, an environment marker (live or test), and an opaque random tail:
ogf_live_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6ogf_test_abc123def456ghi789jkl012mno345pq
Treat keys as secrets. Anyone with your key can call the API on your account. Rotate immediately if a key is exposed in client code, logs, or version control.
Using a key in requests
Pass the key in the Authorization header as a Bearer token:
curl "https://api.ogfetch.com/extract?url=https://example.com" \-H "Authorization: Bearer ogf_live_..."
Live vs test keys
ogf_live_* keys count against your billed quota and hit real upstream sites. ogf_test_* keys are free-of-charge but return canned responses for a fixed set of fixture URLs — useful for CI and unit tests.
Rotating a key
From the Keys page, click Regenerate. The old key is invalidated immediately and a new key is issued. Update any deployed services within the rotation window.
Rate limits and quotas
Each plan has per-endpoint monthly quotas (see Rate Limiting). All responses include X-RateLimit-* headers so you can monitor consumption in production.
Errors
Authentication-related responses use these status codes — see the full Errors reference for the complete list:
401 Unauthorized— missing key, or theAuthorizationheader is malformed.403 Forbidden— key exists but doesn't have access to the requested endpoint or scope.429 Too Many Requests— quota exceeded for the current billing period.