# Using the API

> Create an API key in Hiresweep and use it to call the REST API from scripts and integrations.

The Hiresweep API gives scripts and integrations access to your resumes, job applications, job searches and agent chats. Every request is authenticated with an API key you create in **Settings**.

The [API reference](https://docs.hiresweep.com/api-reference/introduction) lists every endpoint with its parameters and responses.

## Create an API key

<Steps>
  <Step title="Open API keys">
    Sign in at [hiresweep.com](https://hiresweep.com), open **Settings** and select **API keys** under **Developers**.
  </Step>

  <Step title="Select Create API key">
    In the dialog, fill in:

    - **Name**: a label that tells you what the key is for, up to 64 characters.
    - **Expires in**: **1 month** (the default), **3 months**, **6 months** or **1 year**.

    Select **Create API key**.
  </Step>

  <Step title="Copy the key">
    Select **Copy API key** and store the key somewhere safe, such as a password manager or your deployment's secrets.

    <Warning>
      The key is shown only once. If you lose it, delete it and create a new one.
    </Warning>
  </Step>
</Steps>

Your keys are listed under **Your API keys** with their name, the start of the key and when they expire. An expired key shows **Expired** and stops working.

<Warning>
  API keys have full access to your account. A key can do anything you can do through the API, including deleting
  resumes and sending applications, and it can't be limited to some actions. Treat it like a password. To give an AI
  assistant limited access instead, connect it over [MCP with OAuth](https://docs.hiresweep.com/guides/using-the-mcp-server).
</Warning>

## Authenticate requests

Send the key in the `x-api-key` header. The API is served under `https://hiresweep.com/api/openapi`.

```bash
curl "https://hiresweep.com/api/openapi/resumes" \
  -H "x-api-key: YOUR_API_KEY"
```

A missing, wrong or expired key returns `401 Unauthorized`.

## Rate limits

| Limit | Applies to |
| --- | --- |
| 1,000 requests per hour | Each API key, across every endpoint. Past the limit, requests with that key return `401 Unauthorized` for up to an hour. |
| 300 requests per minute | Creating and changing resumes, per resume. |
| 20 requests per minute | AI endpoints, such as parsing a PDF or analyzing a resume. |
| 5 requests per minute | Downloading the same resume as a PDF. |

The per-minute limits return `429 Too Many Requests`.

Calls that use Hiresweep AI also use AI actions from your plan, the same as in the app. See [Plans and usage](https://docs.hiresweep.com/guides/plans-and-usage).

## Delete an API key

In **Settings** → **API keys**, select **Delete API key** next to the key and confirm. Scripts and integrations using the key lose access at once. This can't be undone.

## Related

- [Using the Patch API](https://docs.hiresweep.com/guides/using-the-patch-api) for small, targeted changes to a resume.
- [JSON resume schema](https://docs.hiresweep.com/guides/json-resume-schema) for the shape of resume data.
- [Using the MCP server](https://docs.hiresweep.com/guides/using-the-mcp-server) to connect AI assistants.
