Home
Integrations

Get your API key and use the Filemonk API

Find your API key, keep it safe, and know what the API can do.
Last updated

Filemonk has an API for connecting your own systems: creating and updating assets, reading orders, attaching files to an order, and checking licence keys. Requests authenticate with a private API key from your settings.

Before you begin

Treat the key like a password. Anyone holding it can act on your store's Filemonk data, so keep it out of client-side code, public repositories, and screenshots.

Get your key

  1. Click Filemonk in the left menu of your Shopify admin.
  2. Click Settings in the app's menu, then find the API section.
  3. Copy the API Key.

Send it with each request in the X-Auth-Token header.

Reset it

If the key has leaked, or someone with access has left, click Reset. This invalidates the current key immediately, and any integration still using the old key stops working until you update it. Have the replacement ready to deploy before you reset.

What the API covers

The reference documents the endpoints in full. Broadly:

AreaTypical use
AssetsCreate, update, replace, and delete files programmatically
Digital productsManage products and notify their buyers
OrdersRead orders, attach or detach files, trigger a notification
Licence keysCheck a key's status, which is how licensing software verifies an autogenerated key

Checking licence keys is the most common reason merchants reach for the API. See Check licence key status.

Check your setup

Make a simple read request with your key and confirm you get data rather than an authentication error. If it fails, the key is wrong, has been reset, or the header name is not exactly X-Auth-Token.

Troubleshooting

Requests are rejected as unauthenticated

Check the header name and that the key was copied whole. Then check whether the key has been reset since your integration was built, which invalidates it immediately.

My integration broke suddenly

Someone reset the key. Copy the current one and update your integration.

Failed to reset API key

Reload the page and try again. If it keeps failing, contact support rather than leaving a possibly compromised key in place.

Autogenerated licence keys don't validate

Your software has to check them through the API, since they are created by Filemonk rather than your licensing system. See Assign licence keys to a product.

FAQ

Is there one key per store?

Yes, one private key per store. There are no per-user or scoped keys, which is why resetting affects every integration at once.

Can I use it from a browser or a storefront?

No. Anything client-side exposes the key to your customers. Call the API from your server.

Where is the full endpoint reference?

In Filemonk's API documentation, which lists endpoints, parameters, and responses. This article covers getting and protecting the key.

Should I reset it periodically?

Only when there is reason to: a leak, or someone with access leaving. Every reset requires updating each integration.