SNotesSNotes Docs

API Authentication

How to create personal API tokens and authenticate requests to the SNotes Public REST API.

Requests to the SNotes Public REST API must be authenticated with a Personal API Token.


Generating an API Token

You can generate, name, and revoke personal API tokens directly in your SNotes account settings.

Open Account Settings

Log in to your SNotes web app at app.snotes.io and open the Settings page (click the gear icon or navigate to /settings).

Go to API Tokens

Scroll to the API Tokens section. You must be on a Pro plan to create tokens.

Create a New Token

Click Create Token. Enter a memorable description (for example, Automations Server or Raycast Extension).

Copy Your Secret Token

Copy the generated token string. It starts with the prefix sn_live_:

sn_live_a1b2c3d4e5f6...

SNotes only displays the raw token once. It is stored on the server as a salted SHA-256 hash. If you lose your token, revoke it and create a new one.


Authentication Headers

You can supply your API token in any of the following three ways on every request:

Authorization: Bearer sn_live_xxxxxxxxxxxxxxxxxxxxxxxx

2. Token Authorization Header

Authorization: Token sn_live_xxxxxxxxxxxxxxxxxxxxxxxx

3. Custom X-Api-Token Header

X-Api-Token: sn_live_xxxxxxxxxxxxxxxxxxxxxxxx

Code Examples

curl -X GET "https://api.snotes.io/v1/public/notes/" \
  -H "Authorization: Bearer sn_live_xxxxxxxxxxxxxxxxxxxxxxxx" \
  -H "Accept: application/json"

Personal API Tokens vs. MCP Tokens

SNotes separates REST API tokens from Model Context Protocol (MCP) tokens for enhanced security and least privilege:

FeaturePersonal API TokensMCP OAuth Tokens
Token Prefixsn_live_...mcpat_...
Surface/v1/public/* (REST API)/v1/mcp (MCP Server)
GenerationUser Settings → API TokensUser Settings → MCP Clients & OAuth Token Grant
Primary UseScripts, CLI tools, webhooks, cURLClaude Desktop, Cursor, Zed, AI Agents

If you attempt to use an MCP access token (mcpat_...) against the REST API, the server will return a 401 error explaining that a personal API token (sn_live_...) is required.


Token Revocation

You can revoke an API token at any time in Settings → API Tokens. Once revoked:

  • All subsequent requests using that token will immediately fail with HTTP 401 Unauthorized.
  • Active notes and user account data remain completely unaffected.

On this page