Get your API key and use the Filemonk API
Filemonk has an API for connecting your own systems: creating and updating assets, reading orders, attaching files to an order, and checking licence keys. Requests authenticate with a private API key from your settings.
Before you begin
Treat the key like a password. Anyone holding it can act on your store's Filemonk data, so keep it out of client-side code, public repositories, and screenshots.
Get your key
- Click Filemonk in the left menu of your Shopify admin.
- Click Settings in the app's menu, then find the API section.
- Copy the API Key.
Send it with each request in the X-Auth-Token header.
Reset it
If the key has leaked, or someone with access has left, click Reset. This invalidates the current key immediately, and any integration still using the old key stops working until you update it. Have the replacement ready to deploy before you reset.
What the API covers
The reference documents the endpoints in full. Broadly:
| Area | Typical use |
|---|---|
| Assets | Create, update, replace, and delete files programmatically |
| Digital products | Manage products and notify their buyers |
| Orders | Read orders, attach or detach files, trigger a notification |
| Licence keys | Check a key's status, which is how licensing software verifies an autogenerated key |
Checking licence keys is the most common reason merchants reach for the API. See Check licence key status.
Check your setup
Make a simple read request with your key and confirm you get data rather than an authentication error. If it fails, the key is wrong, has been reset, or the header name is not exactly X-Auth-Token.
Troubleshooting
Requests are rejected as unauthenticated
Check the header name and that the key was copied whole. Then check whether the key has been reset since your integration was built, which invalidates it immediately.
My integration broke suddenly
Someone reset the key. Copy the current one and update your integration.
Failed to reset API key
Reload the page and try again. If it keeps failing, contact support rather than leaving a possibly compromised key in place.
Autogenerated licence keys don't validate
Your software has to check them through the API, since they are created by Filemonk rather than your licensing system. See Assign licence keys to a product.
FAQ
Is there one key per store?
Yes, one private key per store. There are no per-user or scoped keys, which is why resetting affects every integration at once.
Can I use it from a browser or a storefront?
No. Anything client-side exposes the key to your customers. Call the API from your server.
Where is the full endpoint reference?
In Filemonk's API documentation, which lists endpoints, parameters, and responses. This article covers getting and protecting the key.
Should I reset it periodically?
Only when there is reason to: a leak, or someone with access leaving. Every reset requires updating each integration.
Related guides
- Check licence key status, the most common API use.
- Assign licence keys to a product, for autogenerated keys.
- Manage your files, for the same work in the app.

