Skip to main content
The public API powers the CLI and the hosted MCP transport.

Base URL

OpenAPI

  • OpenAPI JSON: https://api.nylio.app/api/public/v1/openapi.json
  • HTML docs: https://api.nylio.app/api/public/v1/docs
  • Markdown guide JSON: https://api.nylio.app/api/public/v1/markdown-guide
The API reference section in this site is generated from the hosted OpenAPI document.

Authentication

The public API supports two authentication methods. Each request must use exactly one. Sending both a bearer token and an API key in the same request returns 400 invalid_request.

OAuth bearer tokens

The public REST API expects bearer tokens for this audience:
Available scopes:
  • workspace:read
  • document:read
  • document:write
  • search:read

API keys

For scripts and direct API usage, you can create API keys in the developer settings. Send the key in the x-api-key header:
When you create an API key, you choose which scopes it has. If a key lacks the scope required by an endpoint, the server returns 403 insufficient_scope.

Rate limits

All public API rate limits are enforced per IP address. Responses include these headers:

Covered endpoints

Workspace targeting

Several endpoints accept optional query parameters to target a specific workspace: These parameters are supported on: GET /workspaces/current, GET /documents, GET /documents/{id}, POST /documents/export, and GET /search.

Search query parameter

The GET /search endpoint expects the search term in a query parameter named q:

Export options

POST /documents/export accepts an optional fileName field in the request body to control the output file name.

Write semantics

  • Read endpoints can access workspaces and documents available to the authenticated user.
  • Create, edit, and replace endpoints are limited to personal documents owned by the authenticated user.
  • Document write endpoints use Nylio enhanced markdown.
  • Create, edit, and replace responses return compact document summaries. Call GET /documents/{id} to read the full body.
  • Export returns standard markdown text or base64-encoded binary payloads for PDF and DOCX.
Read the Nylio markdown guide before constructing write payloads. Plain markdown is not accepted by write endpoints.
POST write endpoints (/documents, /documents/edit, /documents/replace) are not covered by the public-api-read rate limit rule. They still require authentication and scope checks but do not have a separate published rate limit at this time.