تخطَّ إلى المحتوى

Authentication

هذا المحتوى غير متوفر بلغتك بعد.

Authentication Method

GhostMind uses Bearer token authentication for the Product API:

Terminal window
Authorization: Bearer gmk_live_...

API Key Types

TypeScopeUse Case
Human-ownedPer userPersonal API access
Service-ownedPer workspaceApplication integration

Scopes

Backward-compatible model: a key with no resource scopes has full data-plane access (all keys issued before scopes existed keep working). Once a key declares at least one resource scope, it is restricted to the families it names:

ScopeEndpoint family
chatPOST /v1/chat/completions
conversations/v1/conversations*, /v1/messages/*
audio/v1/audio/*
projects/v1/projects*
assets/v1/assets/*
usageGET /v1/usage
actions:readGET /v1/actions* (always requires this scope)
actions:runPOST /v1/actions/{slug}/runs, cancellations
adminBypasses all scope checks (operator keys)

Discovery endpoints (/v1/models, /v1/capabilities, /v1/connections, /v1/health) accept any valid key regardless of scopes.

A key without a required scope gets 403 Missing scope: <scope>. Ask your workspace admin to grant scopes when the key is issued — POST /admin/v1/tenants/{id}/api-keys or /me/v1/workspaces/{id}/api-keys accept a scopes array.

Security Best Practices

  • Never commit API keys to version control
  • Use environment variables to inject keys
  • Revoke keys when no longer needed
  • Use scoped keys with minimum required permissions
  • Don’t expose keys in client-side code

Next Steps