Getting started

Authentication

Create an Etchv API key with only the permissions your integration needs, keep it on your server, and fix common API authentication errors.

Send your API key in the X-API-Key header. Store it in your server’s secret manager, a tool that keeps passwords and keys safe.

Shell
curl https://api.etchv.com/watermarks/images/detect \
  -H "X-API-Key: $ETCHV_API_KEY" \
  -F 'file=@watermarked.png'

Create a key

  1. Open API keys and select your organization.
  2. Choose only the permissions (scopes) your integration needs.
  3. Copy the secret or download its CSV before you close the confirmation screen. Etchv shows it only once.
ScopePermission
watermarks:embedWatermark images, PDFs and video
watermarks:detectDetect watermarks in supported media
assets:readList, inspect and download assets
assets:writeRename assets and replace metadata
assets:deleteDelete assets; owner/admin membership also required
webhooks:readInspect endpoints and deliveries
webhooks:writeManage endpoints and redeliver events; owner/admin only
storage:readInspect destinations, deliveries and downloads
storage:writeManage/verify connections, move results and retry delivery; owner/admin only
watermarks:embed
Permission
Watermark images, PDFs and video
watermarks:detect
Permission
Detect watermarks in supported media
assets:read
Permission
List, inspect and download assets
assets:write
Permission
Rename assets and replace metadata
assets:delete
Permission
Delete assets; owner/admin membership also required
webhooks:read
Permission
Inspect endpoints and deliveries
webhooks:write
Permission
Manage endpoints and redeliver events; owner/admin only
storage:read
Permission
Inspect destinations, deliveries and downloads
storage:write
Permission
Manage/verify connections, move results and retry delivery; owner/admin only

Each key belongs to one Organization. On every request, Etchv checks Organization membership, whether the key has expired or been revoked, and the key's permissions. To process files, your plan must include the format and you need available credits.

Use keys in the dashboard

The media forms pick an active key from your Organization. Use the dropdown to change it. Keys without the required scope are disabled. Members can select their own keys. Owners and admins can select any Organization key. Your choice lasts until you close the browser session.

You are already signed in, so you don't need to paste a secret. The API examples you can copy match the media, request mode and storage you selected.

Keep credentials on your server

Do not put keys in frontend code, mobile apps, public code repositories or URLs. If a key is exposed, revoke it and create a new one.

Authentication errors

StatusCheck
401Missing, invalid, expired or revoked key
403Scopes, membership or plan access
402Billing and available credits
401
Check
Missing, invalid, expired or revoked key
403
Check
Scopes, membership or plan access
402
Check
Billing and available credits
Check a key without spending credits

GET /auth/api-key accepts any active key in X-API-Key. It returns organization_id, key_id and scopes, with Cache-Control: no-store. It uses no credits and gives no extra permissions.

Job permissions and management access

A job can use an existing webhook or verified storage destination with only its embed or detect scope. Managing those resources needs the scopes above. Managing assets uses no watermarking credits.

Managing your account and Organization needs a signed-in session. API keys cannot do this. Webhooks · Storage.

View source on GitHub

Your privacy, your choice

We use essential cookies to keep Etchv working. Optional analytics helps us improve the site. Analytics is on by default; you can turn it off in preferences. PostHog loads only if you accept all. Privacy policy

ETCHV

Privacy preferences

Choose what you allow on this browser. Analytics is enabled by default. You can turn it off, and change your choice at any time.

Essential

Always active

Supports secure sign-in, account sessions, site security, and remembering your privacy choice. These are needed for Etchv to work.

Analytics

Helps us understand visits and improve the website using page-view and device statistics, which do not use cookies. PostHog also measures visits and campaigns and may set cookies; it loads only after you save a choice with analytics on. Turning this off stops future analytics events.

We do not load advertising scripts. Meeting calendars load only when you open them. These preferences do not change your account, watermarking requests, or asset storage.

Your choice is remembered for 180 days on this browser. Privacy policy