FxEditor
User guideQuickstartDeploymentAPIDesignFxTeX
APIExamplesRight-click menuAccessibilityFxTeX Server
OverviewAPIAccess and keysSelf-hosting
Plugins
OverviewCKEditor 5TinyMCE 6 and 7BloggerAngularFroalaTiptapWordPressMoodleGoogle Docs and SlidesCanvas, Blackboard and LTITiddlyWikiWriting your ownLicensing
How licensing worksAccess and licence keys
fxTeX Server is free for light use and needs no account to try. For anything more it is a licensed service, and each request has to be recognisable as coming from a licence. There are two ways that happens:
| Calling from | Recognised by |
|---|---|
| A website | Its domain, which the browser sends for you. Nothing to add to your pages. |
| An app, a server, or anywhere without a domain | A licence key, sent with each request. |
Both come from a licence. The Essential licence is the one made for fxTeX Server; Professional and Enterprise include it at higher allowances. See licence options, or sign in to find your key in the licence manager.
Websites: register your domain
When you buy a licence you name the domain it is for. That covers the domain and every
subdomain beneath it, however deep — a licence for example.com also covers
www.example.com and docs.eu.example.com, with nothing more to list. A
staging or development host on a different domain is not covered.
There is no code to add. When a browser loads an equation it sends a Referer
header saying which site asked, and that is what we match against your registration:
<img src="https://fxtex.codecogs.com/svg.image?\frac{a}{b}" />
If your site sets a strict referrer policy
Current browsers send just the origin (https://example.com/) by default, which is
all we need. A page that sets no-referrer or same-origin — through
a Referrer-Policy header or a <meta name="referrer"> tag —
sends nothing, and its equations cannot be attributed to it.
You do not need to weaken the policy across your whole site. A referrerpolicy
attribute on the image overrides the page's policy for that request alone:
<img referrerpolicy="origin" src="https://fxtex.codecogs.com/svg.image?\frac{a}{b}" />
Privacy extensions and some corporate proxies strip the header too; those are outside your control and ours.
Check what we receive
Paste this into a page on your site and load it. It asks fxTeX Server what it saw:
<div id="fxtex-check">Checking…</div>
<script>
fetch("https://fxtex.codecogs.com/diagnostics.json", { cache: "no-store" })
.then(r => r.json())
.then(d => {
document.getElementById("fxtex-check").textContent = d.identifies_site
? "OK - fxTeX Server sees this site as " + d.domain
: "No Referer arrived, so these requests cannot be attributed to this site.";
});
</script>
/diagnostics.json
reports the referer as received, the domain derived from it and whether it is registered. Asking
costs nothing against your allowance, and it is never blocked, so you can always find out what is
happening.
Apps and servers: use a licence key
An app is not a browser: nothing attaches a Referer for you, so an app's requests
arrive with nothing to recognise them by. The same is true of a server calling us from a script.
Send your licence key instead, in an X-API-Key header:
curl -H "X-API-Key: fx_pk_your-key-here" "https://fxtex.codecogs.com/svg.image?x%5E2"
iOS and macOS — Swift
let latex = #"x=\frac{-b\pm\sqrt{b^2-4ac}}{2a}"#
// Encode everything, or a space may arrive as '+'.
let query = latex.addingPercentEncoding(withAllowedCharacters: .alphanumerics)!
var request = URLRequest(url: URL(string: "https://fxtex.codecogs.com/svg.image?\(query)")!)
request.setValue("fx_pk_your-key-here", forHTTPHeaderField: "X-API-Key")
URLSession.shared.dataTask(with: request) { data, _, _ in
guard let svg = data else { return }
// ...
}.resume()
Android — Kotlin with OkHttp
val latex = """x=\frac{-b\pm\sqrt{b^2-4ac}}{2a}"""
// URLEncoder writes a space as "+", which fxTeX Server reads as a plus sign.
val query = URLEncoder.encode(latex, "UTF-8").replace("+", "%20")
val request = Request.Builder()
.url("https://fxtex.codecogs.com/svg.image?$query")
.header("X-API-Key", "fx_pk_your-key-here")
.build()
// Off the main thread:
OkHttpClient().newCall(request).execute().use { response ->
val svg = response.body?.string()
}
A WKWebView or Android WebView showing a real page over
https sends a Referer as a browser would, so a registered domain works
there. Content loaded from file://, or from an HTML string with no base URL, has no
origin and sends nothing — use a key.
Where only a URL is possible
Some places let you write an address and nothing else: an <img> tag in an
app's own HTML, a wiki, a CMS field, a document. For those, put the key at the front of the path;
everything after it is unchanged:
<img src="https://fxtex.codecogs.com/fx_pk_your-key-here/svg.image?1+\sin(x^2)" />
The two forms are equivalent, and the header wins if a request carries both. Prefer the header wherever you can: a key in a URL is visible to anyone who can read the page, and is written into every proxy log it passes through.
How many equations
Use is measured as a rate, not a count. Each domain or key has an allowance made of two numbers: a burst — how many equations it can ask for at once — and a rate at which that burst refills. A page asks for every equation it contains in one go, so the burst is what decides whether a maths-heavy page loads in full.
| Licence | Burst | Sustained |
|---|---|---|
| Sandbox (free trial) | 10 | 1 a second |
| Essential | 1,000 | 100 a second |
| Professional | 10,000 | 1,000 a second |
| Enterprise | No limit | No limit |
Unregistered use shares a light allowance of its own — enough for the odd equation in a forum post or a blog, not for a maths-heavy page or a busy site.
The allowance belongs to the domain, not to the reader: every visitor to your site, and every subdomain under one registration, draws on the same one.
Unregistered, and over the limit
Unregistered use is not blocked. A request from a domain we do not recognise,
with no identification at all, or with a key we do not recognise, still renders the equation.
Once the light allowance for unregistered use is spent, it renders with a small notice beneath it asking the site to register, so a visitor sees an
explanation rather than a missing equation. For json the notice is a
notice field instead. Registering removes it from every request your domain or key
makes.
Over the allowance. The one request that is refused is from a registered
domain or key that has gone past its own allowance for the moment. It receives 429
and a Retry-After header giving the seconds until the next request will succeed; an
image request receives a small picture saying so rather than a broken image. It clears by itself
within seconds. A page that trips it every time is heavier than its licence allows —
talk to us rather than working around it.
Summary
| Website | Register your domain; subdomains are included. Keep the Referer, or allow it per image with referrerpolicy="origin". |
| App or server | Send X-API-Key: fx_pk_… with every request. |
| Only a URL | Put the key first in the path: /fx_pk_…/svg.image?… |
More
API — the URL format, output types and options.
How licensing works — which products need a licence, and when.
Licence options — what each licence includes, and what it costs.
CodeCogs®