TurnitPass
價格API部落格
登入工作台免費開始

TurnitPass

Docs

Platform

GeneralAPI KeysUsageBillingNotifications

Docs

Overview快速開始認證API 參考更新日誌

Endpoints

POST/humanizePOST/paraphrasePOST/detectGET/status
Workspace

Manage billing, word balance, API keys, and subscription from one place.

Create a key
Docs menu認證
GeneralAPI KeysUsageBillingNotificationsOverview快速開始認證API 參考更新日誌
AuthenticationBearer keys, shown once

認證

使用 Bearer API 金鑰認證

開發者請求使用 TurnitPass 工作台產生的 API 金鑰。

Auth console

Keep API keys out of the browser.

TurnitPass API calls use a workspace-owned Bearer key. The key belongs in server-only code, while the dashboard remains the place to create, rotate, revoke, and inspect usage.

Key guardrails

How to keep access safe

4 checks

Server only

Send keys from backend routes, workers, jobs, or secure server actions.

Shown once

Copy the generated key immediately and store it in your secret manager.

Rotate safely

Deploy the replacement key before revoking the old production key.

Account scoped

Usage rolls up to the workspace word balance and billing controls.

Bearer request

Header contract

private by default
request
Bearer
fetch('https://turnitpass.com/api/v1/humanize', {
  method: 'POST',
  headers: {
    Authorization: 'Bearer tp_live_your_api_key',
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({ text: draft, language: 'en' })
})
failed auth
failed auth
401
{
  "error": "Invalid or revoked API key.",
  "code": "invalid_api_key"
}
01Generate in workspace
02Store in secrets
03Call from server
04Rotate or revoke

API keys

在每次請求中傳送 `Authorization: Bearer tp_live_...`。金鑰僅在建立時顯示一次,之後安全加密儲存,且隨時可在工作台撤銷。

Authorization header
Bearer
Authorization: Bearer tp_live_your_api_key
Content-Type: application/json

POST /api/v1/humanize
Keys are shown once when created and can be revoked from the workspace without changing the Google login account.

Managing keys

01

Create

Generate a named key from the workspace and copy it immediately.

02

Revoke

Disable a key instantly. Revoked keys cannot be used for new requests.

03

Rate limits

Each key can be rate-limited independently while usage rolls up to the account.

04

Billing

All keys share the account word balance and subscription limits.

Workspace owned

Key lifecycle

1

Create a named key

Use a name that describes the environment or app surface, such as Production backend, Staging worker, or Internal QA.

2

Copy it once into a secret store

TurnitPass displays the key only at creation. Store it in your deployment provider, CI secret manager, or local .env file.

3

Watch usage through status and billing

All keys share the account word balance, while individual key names make it easier to find which integration is active.

4

Rotate before revoking

Create a replacement key, deploy it, confirm traffic is healthy, then revoke the old key from the workspace.

Environment setup

Store TurnitPass keys as server-only secrets. The examples below use generic names so they can fit Next.js, Workers, server jobs, or any backend runtime.

.env
server only
TURNITPASS_API_KEY=tp_live_your_api_key
TURNITPASS_API_BASE_URL=https://turnitpass.com/api/v1
Local development
.env.local or local secret managerUse a non-production key with a small word budget and clear name.
Preview deploys
Staging keyKeep preview traffic separate so test jobs do not consume production usage unexpectedly.
Production
Backend-only secretRead the key only from trusted server code. Never pass it to the browser.

Security best practices

Server-side only
Never expose keys in browser codeUse keys from backend services, jobs, or secure server routes.
Environment variables
Use TURNITPASS_API_KEYAvoid hardcoding live keys into source control or client bundles.
Rotate keys
Create a replacement before revokingUse separate keys for production, staging, and development.
Compromise response
Revoke immediatelyCreate a new key from the workspace if a key is leaked.

Authentication errors

Missing header
No Authorization header provided
Bad format
Header does not start with Bearer
Invalid key
Key not found, revoked, or malformed
Too many failures
Repeated failed auth attempts can be rate-limited
401 response
JSON
{
  "error": "Invalid or revoked API key.",
  "code": "invalid_api_key"
}

Next steps

快速開始

Make the first humanization request.

API 參考

Review endpoints, parameters, and response formats.

Get started

支援英文、簡體與繁體中文,一站式提供自然化改寫、AI 檢測、智能潤色與文獻引用服務。

免費開始API
TurnitPass

支援英文、簡體與繁體中文,一站式提供自然化改寫、AI 檢測、智能潤色與文獻引用服務。

產品
  • 學術改寫
  • AI 檢測
  • 論文檢測
  • 教師檢測
  • API
  • 開發者
  • 工作台
資源
  • 方案與價格
  • 學術部落格
  • 工具對比
  • 更新日誌
  • 關於我們
  • 聯絡我們
法律
  • 隱私政策
  • 服務條款

© 2026 TurnitPass. All rights reserved.

All systems normal