Get Tools Lab Developer API
Integrate published tools, guides and platform workflows using authenticated developer endpoints. Available capabilities depend on the enabled API modules and your access level.
API options
The platform includes REST endpoints and a lightweight GraphQL-compatible layer, with support for API keys, OAuth client credentials, usage analytics, rate limits and signed webhook delivery. Not every public website feature is automatically available through the API.
Authentication
REST v1 endpoints can use an API key in the X-API-Key header. Newer endpoints may also accept supported bearer tokens. Keep all credentials secret and rotate a key immediately if it is exposed.
curl -H "X-API-Key: qc_your_key" "https://gettoolslab.com/api/v1/tools.php"
Common REST endpoints
Tools
GET /api/v1/tools.php
GET /api/v1/tools.php?category=PDF
GET /api/v1/tools.php?q=json
Guides
GET /api/v1/guides.php
GET /api/v1/guides.php?q=image
REST v2 and GraphQL
The consolidated developer platform can expose newer REST routes and GraphQL operations for supported resources. Use the Developer area and API playground to see the endpoints that are actually enabled on the current deployment.
Rate limits
API requests may be limited per minute or per day. A request that exceeds its limit can return HTTP 429 Too Many Requests together with retry or reset information. Applications should use backoff rather than immediately repeating failed requests.
Webhooks
Supported events can be delivered to an HTTPS webhook destination. Where signing is enabled, verify the HMAC signature before trusting the payload. A webhook consumer should also tolerate retries and should make event processing idempotent so the same delivery does not create duplicate actions.
Errors
Invalid credentials, disabled clients, exhausted quotas or malformed requests can return structured JSON errors with HTTP 4xx status codes. Server-side failures use 5xx responses. Applications should log the response status and request identifier where available rather than exposing secret credentials in error reports.
Security guidance
- Never embed secret API keys in public browser JavaScript.
- Use HTTPS for API and webhook traffic.
- Give clients only the permissions they require.
- Validate webhook signatures.
- Rotate compromised credentials.
- Respect documented rate limits and file-size limits.
SDKs and playground
Visit the Developer section for SDK examples and the interactive playground. Test integrations with non-sensitive data before using production files or customer information.