Skip to content

Start

Authentication

Every request carries an API key as a bearer token. Keys are created and revoked in the dashboard.

API keys

Create keys under API keys in the dashboard, once you have accepted the Terms of Service there. A key looks like dk_live_ followed by a 16-character key id, an underscore and a 48-character secret:

dk_live_<16-character key id>_<48-character secret>

The dashboard shows the key once, when you create it; afterwards it shows only the prefix (dk_live_ plus the key id), which is safe to log. We keep only a one-way hash of the secret, so a lost key cannot be recovered: revoke it and create another.

Send the key in the Authorization header of every request. This one lists your task models and costs nothing:

GET /v1/task-models
Python
import os
import requests
response = requests.get('https://dydema--eegapi-gateway.modal.run/v1/task-models', headers={"Authorization": f"Bearer {os.environ['DYDEMA_API_KEY']}"}, timeout=30)
response.raise_for_status()
print(response.json())
Keep keys on your servers: in an environment variable or a secret manager, never in a URL, a browser or mobile app, or a repository. If one leaks, revoke it in the dashboard straight away; anything it was used for is billed to your account.

What a key can do

Keys created in the dashboard can call:

EndpointPermission
/v1/task-models (create, predict, list, expire, delete)predictions
GET /v1/task-modelsmodels:read
GET /v1/usageusage:read

That is the whole public API: Wizard’s task models, and your usage. A key without the permission an endpoint needs gets 403 SCOPE_MISSING.

One account, shared limits

Rate limits and spending caps belong to your account, not to a key: all your keys share them, and revoking a key does not reset them. See Errors & limits.

Replacing a key

Revoking takes effect on the next request. To swap keys without downtime, create the new key, deploy it, then revoke the old one; both work in between.

Authentication errors

CodeStatusMeaning
UNAUTHENTICATED401No key, a malformed key, or one the API does not recognize.
KEY_REVOKED401The key was revoked.
KEY_EXPIRED401The key passed its expiry date.
SCOPE_MISSING403The key lacks the permission this endpoint needs.
TENANT_SUSPENDED403The account is paused, usually after a failed payment. Update your card under Billing.
IP_NOT_ALLOWED403The key is restricted to other IP addresses.