Getting Started
PasteMyst has an open and free API that allows you to do anything that you can do through the UI (pretty much).
This is the documentation for the latest version of the API (V3). Version 2 is deprecated and will be removed at some point in the future, and version 1 is now removed.
The base URL for the API is https://paste.myst.rs/api/v3.
You don't need an API key to access the API, this of course means you will be able to do only what anonymous users can do. To be able to create private pastes, edit pastes, and so on, you will need to get an API key. To get one, log in on the website, go to settings, and select the "access tokens" menu (https://paste.myst.rs/settings/access_tokens). Access tokens are scoped, so you can give it the permissions you need exactly.
In these docs, whenever it says that you must be logged in to do something, it means you must provide an access token.
The V2 API is still working, but it is deprecated. You can view the docs here.
The V1 API is now removed.
Conventions
Authorization
To use the access token send it in the Authorization header like so:
Authorization: Bearer <token>
V3 access tokens look like <8 character id>-<secret>.
Sending just the token without Bearer also works (that's needed for API keys migrated from V2). Note that Bearer is matched case-sensitively, so bearer <token> won't work.
An invalid or expired token doesn't return an error, the request is just treated as if you're not logged in. So if you get an unexpected 401 or 404, double check your token.
Scopes
These are the scopes an access token can have:
paste- read and write access to your pastespaste:read- read access to your pastesuser- read and write access to your user infouser:read- read access to your user infouser:access_tokens- read and write access to your access tokens
paste includes everything paste:read allows, and user includes everything user:read allows.
A missing scope usually returns 403 with the message Missing required scope <scope>. (reading a private paste without the scope returns 404 instead, so it's not exposed that the paste exists).
Errors
Errors are returned as JSON with the HTTP status code and a message:
{
"statusCode": 404,
"message": "Paste not found"
}
Invalid request bodies (like a title that's too long, or a missing required field) return 400 with the same shape, the message contains the validation errors.
Unexpected errors return 500 with the message Internal server error..
The V2 API has its own error format, see the V2 docs.
Rate limits
Requests are rate limited per client IP. The limits work as token buckets:
- all requests: you can make a burst of up to 100 requests, refilling at 30 requests per second
- creating pastes: on top of the general limit, a burst of up to 5 pastes, refilling at 1 paste per minute
After exceeding a rate limit you will get a 429 (Too Many Requests) response, with a Retry-After header (in seconds) and this body:
{
"statusCode": 429,
"message": "Too many requests, please slow down."
}
Encrypted pastes
To read (or edit) an encrypted paste, send the encryption key in the Encryption-Key header:
Encryption-Key: <key>
(The website instead uses a pastemyst-encryption-key-<pasteId> cookie, which works too.)
- no key:
400withMissing encryption key - wrong key:
400withInvalid encryption key. - pastes encrypted back on V2 can return
503withToo many encrypted pastes are being opened right now, please try again in a moment.when a lot of them are being decrypted at once, just retry a bit later