Authentication
Every /v1 call carries an account API key in the Authorization header:
Authorization: Bearer pl_...Write Bearer exactly like that, then one space, then the key. The word is case-sensitive.
API keys
Section titled “API keys”A key is pl_ followed by 32 letters, digits, - and _. Create one on the API keys page of the app, with a label that names the system that will use it.
- The app shows the full key once, when you create it. Prismlet stores a hash of it and its first 11 characters,
pl_plus 8, which the app shows so you can tell keys apart. Nobody can show you the full key again. If you lose a key, create a new one and revoke the old one. - A key belongs to the account, not to a prism or a person. It can run and read every prism and result in the account, including those made in the app.
- There are no scopes and no per-prism keys. To tell systems apart, give each its own key. The API keys page shows when each key was last used and the results it made.
Revoking a key
Section titled “Revoking a key”Revoke a key on the API keys page. The next request that uses it answers 401 with Invalid API key. A call already waiting on the model when you revoke still finishes and saves its result. Results the key made stay in the account.
To rotate a key without downtime, create the new key, deploy it, check its last use in the app, then revoke the old one.
Keep keys on your server
Section titled “Keep keys on your server”Load the key from an environment variable or your secret store, and send requests from your backend. Never put a key in a web page, a mobile app or a repository. Anyone who has it can run your prisms and read your results.
The /v1 API sends no CORS headers, so a browser blocks any call a web page makes to it. If your front end needs answers, have it call your backend, and let your backend call Prismlet.
Authentication errors
Section titled “Authentication errors”| Request | Status | message |
|---|---|---|
No Authorization header, or not Bearer <key> |
401 |
Authentication required |
A key that doesn't start with pl_ |
401 |
Invalid API key |
| An unknown or revoked key | 401 |
Invalid API key |
The code is unauthorized in each case. The API checks the path, format and body before the key, so a malformed request answers 400 even without a key.