Authentication
The base URL, API keys, and the headers of a request.
Base URL
https://api.openinstinct.devAll endpoints are under /v1, take JSON and return JSON.
| Endpoint | |
|---|---|
POST /v1/systemone | Answer questions about a state |
POST /v1/systemone/batch | Many requests in one call |
GET /v1/models | The models you can use |
API keys
Every request carries a key in the Authorization header:
curl https://api.openinstinct.dev/v1/models \
-H "Authorization: Bearer $OPENINSTINCT_API_KEY"Keys are created in the console under API keys.
- A key starts with
oi-. The full secret is shown once, when the key is created. Only a hash of it is stored, so a lost key cannot be recovered: create a new one. - A key belongs to a workspace. All keys of a workspace share its balance, its usage and its rate limits.
- Revoking a key in the console stops it at once.
A missing, wrong or revoked key gets 401:
{
"error": { "code": "invalid_api_key", "message": "Missing or invalid API key. Send Authorization: Bearer <key>." },
"detail": "Missing or invalid API key. Send Authorization: Bearer <key>."
}Keep keys on the server
Do not put a key into a web page, a mobile app or a public repository. Call the API from your backend and keep the key in an environment variable or a secret store.
Request headers
| Header | |
|---|---|
Authorization: Bearer oi-... | Required |
Content-Type: application/json | For POST requests |
x-request-id | Optional. Your own id for the request (letters, digits, ., _, -; up to 128 characters). It is returned in the response; without it the server makes one |
Response headers
| Header | |
|---|---|
x-request-id | The id of the request. Include it when you report a problem |
server-timing | Where the time went, in milliseconds |
x-ratelimit-limit-requests | Your workspace's requests per minute |
x-ratelimit-limit-concurrent | Your workspace's concurrent requests |
x-ratelimit-remaining-requests | Requests left in the current minute |
retry-after | On 429 and some 503: seconds to wait before retrying |