Faturapdf Brazilian Invoice Receipt Pdf Api Authentication

Authentication

A single API key in a header, issued and validated by the RapidAPI gateway. FaturaPDF issues no credentials of its own, stores no accounts, and cannot rotate or revoke a key — that is entirely RapidAPI's surface. Derived from the OpenAPI securitySchemes and upgraded from the provider's api-onboarding descriptor (aod 0.1) and integration guides.

FaturaPDF — Brazilian Invoice & Receipt PDF API secures its APIs with apiKey across 2 declared security schemes, as derived from its OpenAPI definitions.

InvoicesReceiptsPDF GenerationDocumentsBrazilBillingCPF ValidationCNPJ ValidationPixFintechData Validation
Methods: apiKey Schemes: 2 OAuth flows: API key in: header

Security Schemes

RapidAPIKey apiKey
· in: header (X-RapidAPI-Key)
RapidAPIHost apiKey
· in: header (X-RapidAPI-Host)

Source

Authentication Profile

Raw ↑
generated: '2026-08-09'
method: searched
source: openapi/faturapdf-brazilian-invoice-receipt-pdf-api-openapi-original.yml
docs:
  - https://faturapdf.com/.well-known/api-onboarding
  - https://faturapdf.com/guides/generate-invoice-pdf-nodejs/
  - https://faturapdf.com/terms/
description: >-
  A single API key in a header, issued and validated by the RapidAPI gateway. FaturaPDF issues
  no credentials of its own, stores no accounts, and cannot rotate or revoke a key — that is
  entirely RapidAPI's surface. Derived from the OpenAPI securitySchemes and upgraded from the
  provider's api-onboarding descriptor (aod 0.1) and integration guides.
summary:
  types:
    - apiKey
  api_key_in:
    - header
  oauth2_flows: []
schemes:
  - name: RapidAPIKey
    type: apiKey
    in: header
    parameter: X-RapidAPI-Key
    required: true
    env: RAPIDAPI_KEY
    description: >-
      The consumer's personal RapidAPI application key — the only credential a consumer of this
      API sends. Obtained by subscribing to any plan (including the free 20 documents/month
      Basic plan, which asks for no card) on the RapidAPI listing; the key is shown immediately
      in the request builder. A missing or invalid key is rejected by the gateway with HTTP 401.
    sources:
      - openapi/faturapdf-brazilian-invoice-receipt-pdf-api-openapi-original.yml
  - name: RapidAPIHost
    type: apiKey
    in: header
    parameter: X-RapidAPI-Host
    required: false
    value: brazilian-invoice-receipt-pdf-api-cpf-cnpj.p.rapidapi.com
    description: >-
      Optional companion header, always present in RapidAPI's generated code snippets. Accepted
      and recommended for compatibility with RapidAPI SDKs, but not required when addressing the
      gateway subdomain directly — X-RapidAPI-Key alone is sufficient, which the provider states
      was verified against the live gateway.
    sources:
      - openapi/faturapdf-brazilian-invoice-receipt-pdf-api-openapi-original.yml
applied_to: >-
  Global security requirement — every operation, including healthCheck, requires RapidAPIKey when
  called through the gateway.
issuance:
  owner: RapidAPI
  application_noun: API key
  mechanism: marketplace subscription (self-serve)
  signup: https://rapidapi.com/leosanchees2014/api/brazilian-invoice-receipt-pdf-api-cpf-cnpj
  one_time_display: false
  rotation: >-
    Rotate or revoke from the RapidAPI dashboard. FaturaPDF neither issues nor stores keys and
    cannot help with rotation, quota or refunds.
scopes:
  model: quota-tiers
  note: >-
    No per-scope permissions exist. Every plan, including the free one, reaches both endpoints and
    every field; tiers gate monthly document volume only. No scopes/ artifact is emitted.
origin_enforcement:
  detail: >-
    The origin host faturapdf.com is not directly callable. Requests that did not arrive through
    the RapidAPI gateway are rejected with HTTP 401 {"error":"unauthorized"}. Internally the
    gateway injects a private proxy secret so the origin can reject non-gateway traffic; that
    header is never set by, visible to, or relevant for the consumer, and the provider
    deliberately excludes it from the public contract.
  public_exception: >-
    https://faturapdf.com/health is public and unauthenticated on the origin — the one endpoint
    reachable without a key.
client_side_use:
  allowed: false
  reason: >-
    Server-side credential. CORS is not configured for arbitrary origins, and shipping the key to
    a browser bundle lets anyone spend the quota. Proxy through your own backend. A keyless,
    fully client-side alternative exists for one-off documents at https://faturapdf.com/gerador.html.
agent_policy: allowed
agent_policy_source: >-
  https://faturapdf.com/.well-known/api-onboarding — account.agentPolicy "allowed"; the terms page
  states "Automated use is expected and welcome — it is an API — within the quota of your plan."

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/faturapdf-brazilian-invoice-receipt-pdf-api-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.