Developer access

Get Tools Lab Developer API

Integrate published tools, guides and platform workflows using authenticated developer endpoints. Available capabilities depend on the enabled API modules and your access level.

API options

The platform includes REST endpoints and a lightweight GraphQL-compatible layer, with support for API keys, OAuth client credentials, usage analytics, rate limits and signed webhook delivery. Not every public website feature is automatically available through the API.

Authentication

REST v1 endpoints can use an API key in the X-API-Key header. Newer endpoints may also accept supported bearer tokens. Keep all credentials secret and rotate a key immediately if it is exposed.

curl -H "X-API-Key: qc_your_key" "https://gettoolslab.com/api/v1/tools.php"

Common REST endpoints

Tools

GET /api/v1/tools.php
GET /api/v1/tools.php?category=PDF
GET /api/v1/tools.php?q=json

Guides

GET /api/v1/guides.php
GET /api/v1/guides.php?q=image

REST v2 and GraphQL

The consolidated developer platform can expose newer REST routes and GraphQL operations for supported resources. Use the Developer area and API playground to see the endpoints that are actually enabled on the current deployment.

Rate limits

API requests may be limited per minute or per day. A request that exceeds its limit can return HTTP 429 Too Many Requests together with retry or reset information. Applications should use backoff rather than immediately repeating failed requests.

Webhooks

Supported events can be delivered to an HTTPS webhook destination. Where signing is enabled, verify the HMAC signature before trusting the payload. A webhook consumer should also tolerate retries and should make event processing idempotent so the same delivery does not create duplicate actions.

Errors

Invalid credentials, disabled clients, exhausted quotas or malformed requests can return structured JSON errors with HTTP 4xx status codes. Server-side failures use 5xx responses. Applications should log the response status and request identifier where available rather than exposing secret credentials in error reports.

Security guidance

  • Never embed secret API keys in public browser JavaScript.
  • Use HTTPS for API and webhook traffic.
  • Give clients only the permissions they require.
  • Validate webhook signatures.
  • Rotate compromised credentials.
  • Respect documented rate limits and file-size limits.

SDKs and playground

Visit the Developer section for SDK examples and the interactive playground. Test integrations with non-sensitive data before using production files or customer information.