Local editing · Optional cloudMeet Rovty
CONNECT YOUR WORKFLOW

Rovty PDF API

Manage cloud documents, sharing and reviews from your own server. PDF editing and conversion continue to run in the browser.

Start with a token

Sign in to Rovty Cloud → Integrations and create a read-only or read-and-write token. Tokens expire in 30 days, can be revoked immediately, and depend on the Rovty session that created them. Never embed a token in public browser code.

curl https://pdf.rovty.com/api/v1/workspace \
  -H "Authorization: Bearer YOUR_TOKEN"

Upload a PDF

Upload only documents you have permission to store. This saves a private copy in Rovty Cloud. Encode the file name as a URL component.

curl https://pdf.rovty.com/api/v1/files \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/pdf" \
  -H "X-File-Name: document.pdf" \
  --data-binary @document.pdf

Endpoints

MethodPath after /api/v1Purpose
GET/workspaceFiles, links, comments, preferences and usage
POST/filesUpload a PDF; X-Template: true marks a template
GET/files/:idDownload a PDF
PATCH/files/:idRename or change template status
DELETE/files/:idDelete a file, its links and collected signed copies
POST/sharesCreate an expiring view, review or sign link
PATCH/shares/:idRevoke a link
DELETE/shares/:idDelete a link and its completion record
POST/commentsAdd an owner comment
PATCH/comments/:idSet resolved: true or false
DELETE/comments/:idDelete a comment
PUT/preferencesUpdate defaultTool and defaultExpiryDays

Create a share link

{
  "fileId": "UUID_FROM_UPLOAD",
  "label": "Please review",
  "mode": "review",
  "days": 7,
  "password": "optional-long-password"
}

Send this JSON to POST /api/v1/shares. Modes are view, review and sign. The response returns a vault and token once. Build the recipient URL as https://pdf.rovty.com/shared#v=VAULT&t=TOKEN. Link secrets belong in the fragment, never in analytics or logs.

Limits and errors

Free cloud limits are 20 MB per PDF, 100 MB and 50 files per account, 20 templates, 50 links, 200 comments and 5 API tokens. Links expire in 1–30 days. Requests are limited to 60 per minute per client IP across cloud endpoints. A 429 response includes Retry-After. Errors return JSON with an error string: 401 for authentication, 403 for permission, 404 for missing resources, 409 for limits or conflicts, 413 for large uploads and 503 for temporary unavailability. Retry failed uploads carefully: a lost response may follow a completed upload; inspect the workspace before retrying.

Privacy boundaries

Document APIs require a token and return no-store responses. Stored documents are private; sharing requires a link you create. There is no automatic document upload, server conversion API or document training service. Comments and signing names are self-declared. Signature requests do not provide identity verification or certificate-based signing.

Read the full privacy details