How an agent uses Anonify
Follow these steps in order. This is the agent API on https://app.anonify.nl. A person can read this page too.
1. Ask whether an account already exists
Ask the person whether they already have a Anonify account.
If they do, do not call signup. Skip the new-account step and use the existing-account step.
2. New account
If they do not have an account, POST https://app.anonify.nl/api/v1/auth/signup with the JSON below. Omit password. Do not add a password field.
username is letters and numbers only. The server stores it in lowercase. It cannot be changed.
The response includes token, user, and userKey. userKey is the API key. It starts with ank_.
The account gets a company named My company and a workspace named My workspace.
The first time the person opens the app, it asks them to set a password.
If signup says the email already exists, stop. The server message is "Username or Email already exists!". Do not sign up again. Ask for a key and use the existing-account step.
POST https://app.anonify.nl/api/v1/auth/signup Content-Type: application/json { "username": "lettersandnumbers", "email": "person@example.com", "isManager": true, "firstName": "", "lastName": "" }3. Existing account
Do not call signup.
The person logs in at https://app.anonify.nl/login and creates one key at https://app.anonify.nl/profile, then pastes that key to you.
The key starts with ank_. One key is active. A new key replaces the old one.
A 401 means the key is wrong or revoked. Ask for a new key. Do not sign up again.
4. Send the key
Send the key on every request below as Authorization: Bearer ank_...
Use userKey from signup, or the key the person pasted. Do not send the signup token in this header.
Authorization: Bearer ank_...5. Read workspaces
GET https://app.anonify.nl/api/v1/agent-actions/workspaces. The response is the workspaces this key can access.
One workspace is the default. When the response contains one workspace, omit workspaceId on the upload.
When the response contains more than one workspace, the upload must include that workspace id as workspaceId. Ask the person which id to use.
You cannot create a workspace.
GET https://app.anonify.nl/api/v1/agent-actions/workspaces Authorization: Bearer ank_...6. Upload the file
POST https://app.anonify.nl/api/v1/agent-actions/uploads as multipart form data.
Send the file field. PDF, PNG, and JPEG are accepted.
Send workspaceId only when this key can access more than one workspace.
The response is taskId and status.
After this response, give the person the editor link in the last step. Do not wait for processing to finish.
POST https://app.anonify.nl/api/v1/agent-actions/uploads Authorization: Bearer ank_... Content-Type: multipart/form-data file: <PDF, PNG, or JPEG> workspaceId: <only when this key can access more than one workspace>7. Read the job
GET https://app.anonify.nl/api/v1/agent-actions/tasks/{taskId}/job. Replace {taskId} with the taskId from the upload response.
The response includes status, pageCount, and the detected items.
Each item has id, page, text, and redact. An item sometimes also has tag.
GET https://app.anonify.nl/api/v1/agent-actions/tasks/{taskId}/job Authorization: Bearer ank_...8. Accept or reject items
POST https://app.anonify.nl/api/v1/agent-actions/tasks/{taskId}/redactions with JSON accept and reject arrays of item ids.
Send both arrays. At least one id is required, in either array. The other array may be empty.
This updates those items and generates the file.
POST https://app.anonify.nl/api/v1/agent-actions/tasks/{taskId}/redactions Authorization: Bearer ank_... Content-Type: application/json { "accept": ["<item id>"], "reject": [] }9. Download the PDF
GET https://app.anonify.nl/api/v1/agent-actions/tasks/{taskId}/file.
After generation succeeds, the response is the PDF.
Before that, the response is JSON with status. It is not an empty file. Do not save that JSON as a PDF.
GET https://app.anonify.nl/api/v1/agent-actions/tasks/{taskId}/file Authorization: Bearer ank_...10. Read the page limit
GET https://app.anonify.nl/api/v1/agent-actions/limits. The response includes pagesLeft.
Do not start a checkout. Do not pay.
GET https://app.anonify.nl/api/v1/agent-actions/limits Authorization: Bearer ank_...11. Give the person the editor
After upload, give the person https://app.anonify.nl/edit/{taskId}. Replace {taskId} with the taskId from the upload response.
To sign that browser in, add a hash with token and user from the signup response. user is the base64url JSON of the user object.
Build the hash with URLSearchParams. The parameter names are token and user. base64url means UTF-8 JSON, then base64, then replace + with -, replace / with _, and remove = padding.
The editor stays closed and shows the upload progress bar while the document is processing. It then loads itself.
You have token and user only from signup. For an existing account, give https://app.anonify.nl/edit/{taskId} with no hash. The person signs in with their own login.
Do not call the React /media or /tasks routes.
https://app.anonify.nl/edit/{taskId}#token=<signup token>&user=<base64url JSON of user>
Do not do these
- Do not list documents in a workspace.
- Do not pay, and do not start a checkout.
- Do not invite anyone.
- Do not delete anything.
- Do not rename the company.
- Do not create a workspace.
- Do not call the React /media or /tasks routes.
- Do not call signup if the person already has an account, if signup says the email already exists, or if a request returns 401.