Authentication
Authenticate API requests with API keys, choose scopes, and rotate keys safely.
API keys
Section titled “API keys”Server-to-server requests authenticate with an API key in the X-API-Key header:
curl https://api.wirevod.online/v1/assets -H "X-API-Key: wvk_…"Keys look like wvk_<prefix>_<secret>. The wvk_<prefix> part identifies the key and is safe to
show in logs and dashboards; the full key is shown only once, when it’s created. WireVoD
never stores keys in readable form, so a lost key can’t be recovered: create a new one.
Scopes
Section titled “Scopes”Each key carries one scope. Higher scopes include the lower ones.
| Scope | Allows |
|---|---|
read | Read assets and uploads, create and revoke playback sessions |
write | Everything in read, plus create assets and manage uploads |
admin | Everything in write, plus create and revoke API keys |
Give each integration the smallest scope that works. A service that only starts playback for
learners needs read; an upload pipeline needs write.
Managing keys
Section titled “Managing keys”| Action | Request | Scope |
|---|---|---|
| Create | /v1/api-keys with { "name": "…", "scopes": ["read"] } | admin |
| List | /v1/api-keys | any |
| Revoke | /v1/api-keys/{id} | admin |
The create response includes the full key in key. Store it in your secret manager immediately.
Rotating a key
Section titled “Rotating a key”- Create a new key with the same scope.
- Deploy it to your services.
- Revoke the old key with
/v1/api-keys/{id}.
Revoked keys stop working immediately.
User sessions
Section titled “User sessions”People sign in to WireVoD with email and password (or Google). User sessions use short-lived
bearer tokens (Authorization: Bearer …) that refresh automatically. Integrations should always
use API keys instead.
/v1/auth/me returns the identity behind any credential, which is useful to verify a key:
{ "auth": { "kind": "api_key", "key_id": "…", "scopes": ["read"] }, "tenant": { "id": "…", "name": "Acme Academy" }}