Authentication
Personal API keys, scopes, deployment keys, and the account state responses a client should handle.
Authentication Every request to /api/v1/... authenticates one of two ways: a web session for the browser app, or a personal API key for everything else. Inference calls use a third kind of credential, a deployment key. Personal API keys Create a key in Settings , Security , Personal API Keys . It is shown once at creation, starts with sk ... , and can be set to expire between 1 and 365 days or left with no expiry; it can be revoked at any time. Send it as: Creating and revoking a key needs a web session; a personal API key cannot mint or revoke keys itself. Personal API keys need a paid plan; the Free plan does not include them. Scopes A key carries one or more scopes. An umbrella scope satisfies any per-area scope of the same kind a write key can call every write: route , but write never satisfies a read scope and the reverse never happens either. Most read routes accept any scope at all, so do not assume a write-only key cannot read; a few routes accept only the umbrella write scope regardless of area workload audits, deleting or restoring architecture versions, hub file uploads . Scope Covers -------------------------------------- ---------------------------------------------- read Read access to every area below. write Write access to every area below. read:projects / write:projects Projects and architecture versions. read:datasets / write:datasets Datasets. read:training / write:training Training jobs and checkpoints. read:hub / write:hub Hub models and My models the model registry . read:deployment / write:deployment Deployments and inference. read:codegen / write:codegen Code generation. The web app's Read & write CLI, SDK, audits key carries read and write ; Read only carries read . A key missing a required scope answers 403. A key made in the web app before scopes were enforced keeps working: it was upgraded to carry the matching umbrella scope. Deployment keys A deployment has its own key, separate from your personal API keys, sent the same way Authorization: Bearer but only accepted on inference routes. It has no sk prefix, is shown once when the deployment is created or its key is regenerated, and the previous key stops working the moment a new one is minted. See Calling a deployment /docs/deployments/inference . Account state responses A request from an account in one of these states gets a response naming it, instead of a generic failure. The object below arrives under detail , for example "detail": "error": "account suspended", "message": "..." : Status Body Meaning ------ ---------------------------------------------------------------- --------------------------------------------------------------------------------------------------------- 403 "error": "email not verified", "message", "verification url" Verify your email before training, uploading datasets, creating deployments or starting fine-tuning runs. 403 "error": "account suspended", "message" The account has been suspended. 423 "error": "account locked", "message" Sign in only: temporarily locked after repeated failed sign ins; try again later. 401 covers a missing or invalid credential in every other case.
Open in Dagnam.AI docs