Skip to content

Authentication

Every request needs an API key. There is no anonymous access.

Keys are created in the AI4M dashboard under Settings → API access.

You are Who creates keys
In an organisation Its administrators. Keys belong to the organisation, so any administrator can see and revoke them
An independent researcher You, once the AI4M team has unlocked API access for your account. Request it from the same page

When you create a key you choose its name, the data it may read (its scopes), and whether it expires.

Send the key in the Authorization header as a bearer token.

curl https://api.ai4mproject.com/v1/periods \
-H "Authorization: Bearer ai4m_live_xxxxxxxxxxxx"

The x-api-key header is also accepted:

curl https://api.ai4mproject.com/v1/periods -H "x-api-key: ai4m_live_xxxxxxxxxxxx"
Key Starts with Use it for
Live ai4m_live_ Real work. Requests count toward your monthly allowance
Test ai4m_test_ Building and trying things out. Returns the same data; requests do not count toward the monthly allowance

Both kinds are limited to the same number of requests a minute. See Limits.

  • Keep keys out of source code, notebooks you share, and browser-side code. Read them from an environment variable or a secrets store.
  • Use a separate key for each system, named after where it is used, so you can revoke one without affecting the others.
  • Give a key only the scopes it needs.
  • Revoke a key from Settings → API access the moment you think it has leaked. It stops working immediately.

A request returns 401 if the key is missing, mistyped, expired or revoked. It also returns 401 if the account that owns the key has been removed, or its organisation has been suspended. See Errors.