---
title: API Authentication Guide
description: To access any GoFax API endpoint, every request must be authenticated using an API Token.
---

[Skip to content](https://support.gofax.com.au/en/api-authentication-guide#main-content)

[Contact us](https://support.gofax.com.au/en/kb-tickets/new?hsLang=en)

[![Gofax-new-logo-180x45-min.png\]](https://support.gofax.com.au/hs-fs/hubfs/Gofax-new-logo-180x45-min.png?width=200&height=50&name=Gofax-new-logo-180x45-min.png)](https://www.gofax.com.au/)

- [Pricing](https://www.gofax.com.au/pricing/#bundle-plan)
- [Contact](https://www.gofax.com.au/contact-us/)
- [Log In](https://clientadmin.gofax.com.au/login.aspx)
- [Sender ID Registration](https://support.gofax.com.au/en/sms-sender-id-registration-guide)

Open main navigation

Close main navigation

- [Pricing](https://www.gofax.com.au/pricing/#bundle-plan)
- [Contact](https://www.gofax.com.au/contact-us/)
- [Log In](https://clientadmin.gofax.com.au/login.aspx)
- [Sender ID Registration](https://support.gofax.com.au/en/sms-sender-id-registration-guide)
- [Contact us](https://support.gofax.com.au/en/kb-tickets/new)
- [Submit Support Ticket](https://support.gofax.com.au/en/kb-tickets/new)

[Submit Support Ticket](https://support.gofax.com.au/en/kb-tickets/new?hsLang=en)

 GoFax Customer Support Guides & FAQs

- There are no suggestions because the search field is empty.

1. [Support Home](https://support.gofax.com.au/en?hsLang=en)
2. [Developers](https://support.gofax.com.au/en/developers?hsLang=en)
3. [Getting Started](https://support.gofax.com.au/en/developers?hsLang=en#getting-started)

# API Authentication Guide

To access any **GoFax API endpoint**, every request must be authenticated using an API Token. This token uniquely identifies your account and authorises your application to interact with GoFax services.

Your **API Token** can be found in your GoFax account under **My Account → API Access**

Depending on the API version you are using, GoFax supports **two different authentication methods:**

- [API v2.0 – Header-Based Authentication (Recommended)](https://support.gofax.com.au/en/api-authentication-guide#recommended)
- [API v1.0 – Query Parameter Authentication (Legacy)](https://support.gofax.com.au/en/api-authentication-guide#legacy)

This guide also covers

- [How to migrate from v1.0 to v2.0](https://support.gofax.com.au/en/api-authentication-guide#migration)
- [How to test authentication](https://support.gofax.com.au/en/api-authentication-guide#testing)
- [Error handling](https://support.gofax.com.au/en/api-authentication-guide#error)
- [API token security](https://support.gofax.com.au/en/api-authentication-guide#token-security)

### API Credentials

Treat your **API Token** like a password. Never share it publicly or store it in client-side code.

[Learn how to create an API token](https://support.gofax.com.au/en/api-access-tokens?hsLang=en)

 

### 1. API v1.0 – Query Parameter Authentication **(Legacy)**

In API v1.0, the API Token must be passed as a URL parameter named token.

This method is still supported for backward compatibility but is no longer recommended due to security limitations (tokens may appear in logs or browser history).

```
curl --location --request PUT 'https://restful-api.gofax.com.au/v1.0/Account/CheckHaveAccess?token=YOUR_API_TOKEN' \--header 'Accept: application/json'
```

 

### 2. API v2.0 – Header-Based API Token Authentication **(Recommended)**

All API v2.0 endpoints require you to include your API Token in the request header:

x-api-token: YOUR\_API\_TOKEN

This method is more secure and is the standard for all new GoFax integrations.

**Example – cURL**

```
curl --location --request PUT 'https://restful-api.gofax.com.au/v2.0/Account/CheckHaveAccess' \--header 'Accept: application/json' \--header 'x-api-token: YOUR_API_TOKEN'
```

### Error Handling

If the API Token is missing, invalid, or improperly formatted, you will receive a:

**HTTP 401 Unauthorised**

**Example JSON Response**

```
{"error": "UNAUTHORISED","message": "Token is not valid"}
```

#### Common Causes

- Header missing (x-api-token not provided)
- Token expired or regenerated
- Typo in the token value
- Using query parameter instead of header for v2.0
- Calling a v2.0 endpoint with a v1.0 authentication method

 

### Best Practices for Securing Your API Token

#### 🔐 Do

- Store the token using environment variables or secure vaults
- Rotate/regenerate tokens periodically
- Use HTTPS always
- Remove tokens from logs and monitoring tools

#### 🚫 Do Not

- Embed tokens in frontend or mobile apps
- Share tokens via email or chat
- Store tokens in code repositories
- Expose tokens in URLs (except when required for legacy v1.0 endpoints)

### Testing Authentication

You can test authentication using:

**Postman**

1. Go to Headers tab
2. Add: Key: x-api-token Value: YOUR\_API\_TOKEN
3. Send a request to a v2.0 endpoint

**Sample Test Endpoint**

PUT https://restful-api.gofax.com.au/v2.0/Account/CheckHaveAccess

Returns:

```
{"Success": true,"Message": "Token valid","ValidationErrors": null,"Response": "YOUR_API_TOKEN"}
```

### Migration Guide: v1.0 → v2.0

If you are updating your integration:

| Feature | v1.0 | v2.0 |
| --- | --- | --- |
| Authentication | ?token=YOUR\_API\_TOKEN | header 'x-api-token: YOUR\_API\_TOKEN' |

To migrate:

1. Replace all v1.0 URLs with v2.0 equivalents
2. Remove ?token=YOUR\_API\_TOKEN
3. Add header: x-api-token: YOUR\_API\_TOKEN
4. Update payloads to match v2.0 schema

If you encounter authentication issues or need assistance integrating with the GoFax API, contact GoFax support. 

- [Fax](https://support.gofax.com.au/en/fax?hsLang=en#main-content)

    - [Sending Fax](https://support.gofax.com.au/en/fax?hsLang=en#sending-fax)
    - [Receiving Fax](https://support.gofax.com.au/en/fax?hsLang=en#receiving-fax)
    - [Fax Broadcast](https://support.gofax.com.au/en/fax?hsLang=en#fax-broadcast)
    - [Fax Number Porting](https://support.gofax.com.au/en/fax?hsLang=en#fax-number-porting)
    - [General](https://support.gofax.com.au/en/fax?hsLang=en#general)
- [SMS](https://support.gofax.com.au/en/sms?hsLang=en#main-content)

    - [Sending](https://support.gofax.com.au/en/sms?hsLang=en#sending)
    - [General](https://support.gofax.com.au/en/sms?hsLang=en#general)
    - [SMS Sender ID Register](https://support.gofax.com.au/en/sms?hsLang=en#sms-sender-id-register)
- [Account](https://support.gofax.com.au/en/account?hsLang=en#main-content)

    - [My Account](https://support.gofax.com.au/en/account?hsLang=en#my-account)
    - [My Settings](https://support.gofax.com.au/en/account?hsLang=en#my-settings)
- [Software and apps](https://support.gofax.com.au/en/software-and-apps?hsLang=en#main-content)

    - [GoFax App](https://support.gofax.com.au/en/software-and-apps?hsLang=en#gofax-app)
    - [GoFax Print Driver](https://support.gofax.com.au/en/software-and-apps?hsLang=en#gofax-print-driver)
- [Developers](https://support.gofax.com.au/en/developers?hsLang=en#main-content)

    - [Getting Started](https://support.gofax.com.au/en/developers?hsLang=en#getting-started)
    - [Webhooks](https://support.gofax.com.au/en/developers?hsLang=en#webhooks)
- [Integrations](https://support.gofax.com.au/en/integrations?hsLang=en)
- [Compliance and Security](https://support.gofax.com.au/en/compliance-and-security?hsLang=en)
- [GoFax Corporate](https://support.gofax.com.au/en/gofax-corporate?hsLang=en)
- [Frequently Asked Questions (FAQs)](https://support.gofax.com.au/en/frequently-asked-questions-faqs?hsLang=en)
- [GoFax (GoLogic) Partners](https://support.gofax.com.au/en/gofax-gologic-partners?hsLang=en)

[![Gofax-new-logo-180x45-min-2](https://support.gofax.com.au/hs-fs/hubfs/Gofax-new-logo-180x45-min-2.png?width=180&height=45&name=Gofax-new-logo-180x45-min-2.png "Gofax-new-logo-180x45-min-2")](http://gofax.com.au)

| [Contact Us](https://www.gofax.com.au/contact-us/) | [1300 928 872](tel:1300%20928%20872) | Intl: [+617 5227 8301](tel:+617%205227%208301) |
| --- | --- | --- |