Skip to content
Docs
Get early access

Authentication

Authenticate API requests with API keys, choose scopes, and rotate keys safely.

Server-to-server requests authenticate with an API key in the X-API-Key header:

Request
curl https://api.wirevod.online/v1/assets -H "X-API-Key: wvk_…"

Keys look like wvk_<prefix>_<secret>. The wvk_<prefix> part identifies the key and is safe to show in logs and dashboards; the full key is shown only once, when it’s created. WireVoD never stores keys in readable form, so a lost key can’t be recovered: create a new one.

Each key carries one scope. Higher scopes include the lower ones.

ScopeAllows
readRead assets and uploads, create and revoke playback sessions
writeEverything in read, plus create assets and manage uploads
adminEverything in write, plus create and revoke API keys

Give each integration the smallest scope that works. A service that only starts playback for learners needs read; an upload pipeline needs write.

ActionRequestScope
Create/v1/api-keys with { "name": "…", "scopes": ["read"] }admin
List/v1/api-keysany
Revoke/v1/api-keys/{id}admin

The create response includes the full key in key. Store it in your secret manager immediately.

  1. Create a new key with the same scope.
  2. Deploy it to your services.
  3. Revoke the old key with /v1/api-keys/{id}.

Revoked keys stop working immediately.

People sign in to WireVoD with email and password (or Google). User sessions use short-lived bearer tokens (Authorization: Bearer …) that refresh automatically. Integrations should always use API keys instead.

/v1/auth/me returns the identity behind any credential, which is useful to verify a key:

Response · 200
{
"auth": { "kind": "api_key", "key_id": "…", "scopes": ["read"] },
"tenant": { "id": "…", "name": "Acme Academy" }
}