API Authentication
How to create personal API tokens and authenticate requests to the SNotes Public REST API.
Requests to the SNotes Public REST API must be authenticated with a Personal API Token.
Generating an API Token
You can generate, name, and revoke personal API tokens directly in your SNotes account settings.
Open Account Settings
Log in to your SNotes web app at app.snotes.io and open the Settings page (click the gear icon or navigate to /settings).
Go to API Tokens
Scroll to the API Tokens section. You must be on a Pro plan to create tokens.
Create a New Token
Click Create Token. Enter a memorable description (for example, Automations Server or Raycast Extension).
Copy Your Secret Token
Copy the generated token string. It starts with the prefix sn_live_:
sn_live_a1b2c3d4e5f6...SNotes only displays the raw token once. It is stored on the server as a salted SHA-256 hash. If you lose your token, revoke it and create a new one.
Authentication Headers
You can supply your API token in any of the following three ways on every request:
1. Bearer Authorization Header (Recommended)
Authorization: Bearer sn_live_xxxxxxxxxxxxxxxxxxxxxxxx2. Token Authorization Header
Authorization: Token sn_live_xxxxxxxxxxxxxxxxxxxxxxxx3. Custom X-Api-Token Header
X-Api-Token: sn_live_xxxxxxxxxxxxxxxxxxxxxxxxCode Examples
curl -X GET "https://api.snotes.io/v1/public/notes/" \
-H "Authorization: Bearer sn_live_xxxxxxxxxxxxxxxxxxxxxxxx" \
-H "Accept: application/json"Personal API Tokens vs. MCP Tokens
SNotes separates REST API tokens from Model Context Protocol (MCP) tokens for enhanced security and least privilege:
| Feature | Personal API Tokens | MCP OAuth Tokens |
|---|---|---|
| Token Prefix | sn_live_... | mcpat_... |
| Surface | /v1/public/* (REST API) | /v1/mcp (MCP Server) |
| Generation | User Settings → API Tokens | User Settings → MCP Clients & OAuth Token Grant |
| Primary Use | Scripts, CLI tools, webhooks, cURL | Claude Desktop, Cursor, Zed, AI Agents |
If you attempt to use an MCP access token (mcpat_...) against the REST API, the server will return a 401 error explaining that a personal API token (sn_live_...) is required.
Token Revocation
You can revoke an API token at any time in Settings → API Tokens. Once revoked:
- All subsequent requests using that token will immediately fail with HTTP
401 Unauthorized. - Active notes and user account data remain completely unaffected.