Authentication
Every request needs an API key. There is no anonymous access.
Get a key
Section titled “Get a key”Keys are created in the AI4M dashboard under Settings → API access.
| You are | Who creates keys |
|---|---|
| In an organisation | Its administrators. Keys belong to the organisation, so any administrator can see and revoke them |
| An independent researcher | You, once the AI4M team has unlocked API access for your account. Request it from the same page |
When you create a key you choose its name, the data it may read (its scopes), and whether it expires.
Send the key
Section titled “Send the key”Send the key in the Authorization header as a bearer token.
curl https://api.ai4mproject.com/v1/periods \ -H "Authorization: Bearer ai4m_live_xxxxxxxxxxxx"from ai4m_sdk import AI4MClient
client = AI4MClient(api_key="ai4m_live_xxxxxxxxxxxx")import { AI4MClient } from "ai4m-sdk";
const client = new AI4MClient({ apiKey: "ai4m_live_xxxxxxxxxxxx" });import ai4m "github.com/ai4m-project/ai4m-api/sdk/go"
client := ai4m.NewClient("ai4m_live_xxxxxxxxxxxx")The x-api-key header is also accepted:
curl https://api.ai4mproject.com/v1/periods -H "x-api-key: ai4m_live_xxxxxxxxxxxx"Live and test keys
Section titled “Live and test keys”| Key | Starts with | Use it for |
|---|---|---|
| Live | ai4m_live_ |
Real work. Requests count toward your monthly allowance |
| Test | ai4m_test_ |
Building and trying things out. Returns the same data; requests do not count toward the monthly allowance |
Both kinds are limited to the same number of requests a minute. See Limits.
Keep keys safe
Section titled “Keep keys safe”- Keep keys out of source code, notebooks you share, and browser-side code. Read them from an environment variable or a secrets store.
- Use a separate key for each system, named after where it is used, so you can revoke one without affecting the others.
- Give a key only the scopes it needs.
- Revoke a key from Settings → API access the moment you think it has leaked. It stops working immediately.
When a key stops working
Section titled “When a key stops working”A request returns 401 if the key is missing, mistyped, expired or revoked. It also returns 401 if the account that owns the key has been removed, or its organisation has been suspended. See Errors.