Authentication
Authorize requests, choose permissions and manage API keys.
Authenticate from your server
Send your business API key in the Authorization header. The key’s business owns the resources. Keep the secret in server-side configuration; never include it in browser code, public repositories or logs.
Request header
http
Authorization: Bearer YOUR_BUSINESS_API_KEYIssued secrets start with ak_. Treat the entire value as opaque. The prefix does not identify an environment or grant permissions.
Permissions
| Scope | Endpoints |
|---|---|
| files:write | Create a file |
| models:read | List models / Get a model / List model file revisions / Calculate prices |
| models:write | Create a model / Update a model / Delete a model / Replace a model file |
| orders:read | List orders / Get an order / Download an order invoice |
| orders:write | Create an order / Cancel an order |
| payments:read | List payment methods |
| payments:write | Pay an order |
| quotes:read | Get a quote |
| quotes:write | Create a quote |
payments:read lists saved cards without authorizing charges. Existing payments:write keys also pass the payments:read check. Starting a payment still requires payments:write and administrator spending consent.
New keys receive the standard resource scopes. Enabling spending adds payments:read and payments:write. Existing keys retain their scopes.
Rotate and revoke keys
- Create a replacement key with the required permissions.
- Update your server configuration and verify a request succeeds.
- Revoke the old key in the account workspace.
Keys expire after the selected 7, 30, 90 or 365 days. Expired keys cannot authenticate. Revocation and permission changes can take up to 30 seconds to affect reads. Writes and payment access check the current key on every request. Revocation does not cancel orders or payments already accepted. If a key is exposed, revoke it and replace it immediately.
Authentication errors
401 unauthenticated means the credential is missing, invalid or expired. A credential that is not an API key receives: Invalid credential. Server integrations use a business API key (ak_…). An invalid API key receives: Invalid API key. A missing header receives: A bearer credential is required. 403 permission_denied means the caller lacks the required permission or spending authorization.
API v1 preview