Authentication
Every request except the public catalog needs an API key, sent as a bearer token.
Sending the key
Put the key in the Authorization header of every request. Keys start with inker_live_.
Authorization: Bearer inker_live_…curl https://api.inker.si/v1/account \
-H "Authorization: Bearer $INKER_API_KEY"Creating a key
Create keys on your account page, in the Developers section. The full key is shown once, right after you create it, so copy it then: inker keeps only a fingerprint of it and can never show it again.
Scopes
A key can only call the endpoints its scopes allow; anything else answers insufficient_scope. Give each key only what it needs.
| Scope | Allows |
|---|---|
generate | Quote, start and cancel generations. Spends coins. |
read | List and read generations and files. |
uploads | Upload input files. |
account | Read your balance and limits. |
Keeping keys safe
- Call the API from your server. Never put a key in a web page, a mobile app or a public repository.
- Set a monthly coin limit on each key. Once a key has spent that many coins in a calendar month (UTC), new generations answer
spend_cap_exceededuntil the next month. - Give keys an expiry date (30, 90 or 365 days). An expired key answers
api_key_expired. - Revoke a key you no longer use or that may have leaked. It stops working at once and answers
api_key_revoked.
Keys and webhooks are managed only from your account page while signed in: an API key can never create keys or read secrets.