Base URL
OpenAPI
- OpenAPI JSON:
https://api.nylio.app/api/public/v1/openapi.json - HTML docs:
https://api.nylio.app/api/public/v1/docs - Markdown guide JSON:
https://api.nylio.app/api/public/v1/markdown-guide
Authentication
The public API supports two authentication methods. Each request must use exactly one. Sending both a bearer token and an API key in the same request returns400 invalid_request.
OAuth bearer tokens
The public REST API expects bearer tokens for this audience:workspace:readdocument:readdocument:writesearch:read
API keys
For scripts and direct API usage, you can create API keys in the developer settings. Send the key in thex-api-key header:
403 insufficient_scope.
Rate limits
All public API rate limits are enforced per IP address.
Responses include these headers:
Covered endpoints
Workspace targeting
Several endpoints accept optional query parameters to target a specific workspace:
These parameters are supported on:
GET /workspaces/current, GET /documents, GET /documents/{id}, POST /documents/export, and GET /search.
Search query parameter
TheGET /search endpoint expects the search term in a query parameter named q:
Export options
POST /documents/export accepts an optional fileName field in the request body to control the output file name.
Write semantics
- Read endpoints can access workspaces and documents available to the authenticated user.
- Create, edit, and replace endpoints are limited to personal documents owned by the authenticated user.
- Document write endpoints use Nylio enhanced markdown.
- Create, edit, and replace responses return compact document summaries. Call
GET /documents/{id}to read the full body. - Export returns standard markdown text or base64-encoded binary payloads for PDF and DOCX.
POST write endpoints (
/documents, /documents/edit, /documents/replace) are not covered by the public-api-read rate limit rule. They still require authentication and scope checks but do not have a separate published rate limit at this time.