API
Call wapgee tools over HTTP with a personal API token. The tools on the site keep running in your browser. The API is a separate, server-side path.
Getting a token
- Sign in. Any role can create a token, including a subscriber. Locked accounts cannot.
- Open Tools, then Tokens in the dashboard.
- Name the token and create it. The full token is shown once. Copy it then. It cannot be retrieved later.
You can hold 5 active tokens. Revoking a token stops it immediately and keeps its usage history. All of your tokens share one allowance per tool.
Authentication
Send the token on every request in the Authorization header:
Authorization: Bearer wpg_your_tokenA missing token, an unknown token, a revoked token, and a token whose account is locked each receive 401. Missing and unknown tokens are not stored. A revoked token or a locked account is stored in usage history and does not count against the allowance.
Limits
Each tool has its own daily allowance, counted per user. The day resets at midnight UTC. Only a successful request counts. A request rejected for validation, the burst limit, or the daily allowance is kept in your usage history and does not count.
Past the daily allowance, the API responds with 429 until the day resets. There is no paid plan to raise a limit.
A separate burst limit of 30 requests per minute applies to each token, on top of the daily allowance. Usage history is kept for 90 days.
Rate limit headers
Authenticated responses include:
| Header | Meaning |
|---|---|
X-RateLimit-Limit | The limit for this response. |
X-RateLimit-Remaining | How many requests are left in the window. |
X-RateLimit-Reset | When the window resets, as unix time in seconds. |
Retry-After | On 429 only. Seconds to wait. For the daily allowance that is the time until midnight UTC. For the burst limit it is the rest of the current minute. |
On a tool request the headers describe that tool's daily allowance. On GET /api/v1/usage they describe the burst limit, and the body lists each tool's allowance.
Errors
Errors use { success: false, error: string } with the matching HTTP status.
| Status | When |
|---|---|
401 | The token is missing, unknown, or revoked, or the account is locked. Missing and unknown tokens are not stored. |
400 | The request was rejected by validation. |
429 | The burst limit or the daily allowance is exceeded. |
500 | Something unexpected failed. |
Check your usage
GET /api/v1/usage returns the limit, used count, remaining count, and reset time for every tool on the API. It does not count against any allowance. The same numbers are on the API tokens tab in Settings.
curl https://wapgee.com/api/v1/usage \
-H "Authorization: Bearer wpg_your_token"{
"success": true,
"tools": [
{
"tool": "example-tool",
"limit": 10,
"used": 2,
"remaining": 8,
"resetsAt": "2026-09-30T00:00:00.000Z"
}
]
}Tool endpoints live at /api/v1/tools/<slug>. Each tool documents its own request and response below when it is added.
Tools
No tool endpoint is published yet.