> ## Documentation Index
> Fetch the complete documentation index at: https://docs.proofage.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Postman collection

> Import the ProofAge API into Postman. The collection signs every request itself.

The collection is generated from the [OpenAPI specification](/openapi.json) and holds all 16 endpoints of the API.

<CardGroup cols={2}>
  <Card title="Fork it in Postman" icon="code-fork" href="https://www.postman.com/proofage/proofage-api/collection/7uussw0/proofage-api">
    The collection on the Postman API Network. Fork it to get its updates.
  </Card>

  <Card title="Download the collection" icon="download" href="/proofage-api.postman_collection.json">
    proofage-api.postman\_collection.json, to import by hand.
  </Card>
</CardGroup>

## Import

1. Fork the collection from ProofAge's Postman profile, or choose **Import** in Postman and drop the downloaded file into the dialog.
2. Open the collection's **Variables** tab. `baseUrl` is already set to `https://api.proofage.net/v1`. Fill in the other two, in the **Current value** column so your keys are not synced to your team:

| Variable | Value |
| - | - |
| `apiKey` | The workspace's public key, `pk_test_…` or `pk_live_…`. |
| `secretKey` | One of the workspace's secret keys. |

Every request is now signed when you send it. Start with **Get workspace configuration**: a `200` means the keys and the signature are right, a `401` means one of them is not.

## How requests are signed

Every request needs `X-API-Key` and `X-HMAC-Signature` (see [API authentication](/getting-started/api-authentication)). The collection's pre-request script adds both. This is the script it runs:

```javascript theme={null}
// Signs every request with the workspace secret key (see API authentication).
// Canonical request: METHOD + path + ("?" + query, if any) + raw body.
const rfc3986 = (value) =>
  encodeURIComponent(value).replace(/[!'()*]/g, (c) => '%' + c.charCodeAt(0).toString(16).toUpperCase());

const apiKey = pm.variables.get('apiKey');
const secretKey = pm.variables.get('secretKey');
if (!apiKey || !secretKey) {
  throw new Error('Set the apiKey and secretKey variables of the ProofAge collection first.');
}
pm.request.headers.upsert({ key: 'X-API-Key', value: apiKey });

const body = pm.request.body;
if (body && body.mode === 'formdata') {
  // A media upload is signed over its fields and the SHA-256 of each file, which a
  // pre-request script cannot read: upload media with a server SDK instead.
  console.warn('ProofAge: media uploads cannot be signed from Postman.');
} else {
  // The sandbox has no URL class: take the path of baseUrl (for example /v1) by hand.
  const basePath = pm.variables.replaceIn('{{baseUrl}}').replace(/^[a-z]+:\/\/[^/]+/i, '').replace(/\/$/, '');
  const path = basePath + pm.variables.replaceIn(pm.request.url.getPath());
  const query = pm.request.url.query
    .filter((param) => !param.disabled)
    .map((param) => [pm.variables.replaceIn(param.key), pm.variables.replaceIn(param.value ?? '')])
    .sort(([a], [b]) => (a < b ? -1 : a > b ? 1 : 0))
    .map(([key, value]) => rfc3986(key) + '=' + rfc3986(value))
    .join('&');
  const raw = body && body.mode === 'raw' ? pm.variables.replaceIn(body.raw) : '';

  const canonical = pm.request.method + path + (query ? '?' + query : '') + raw;
  const signature = CryptoJS.HmacSHA256(canonical, secretKey).toString(CryptoJS.enc.Hex);

  pm.request.headers.upsert({ key: 'X-HMAC-Signature', value: signature });
}
```

<Note>
  A media upload is signed over its form fields and the SHA-256 of each file, which a pre-request script cannot read, so the script leaves uploads unsigned. Upload media with a [server SDK](/integration/sdks) or the signing code in [API authentication](/getting-started/api-authentication).
</Note>

## Next steps

* [Quick start](/getting-started/quick-start): the recommended integration end to end.
* [API reference](/api-reference/overview): conventions and error shapes.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.