Start
Authentication
Every request carries an API key as a bearer token. Keys are created and revoked in the dashboard.
API keys
Create keys under API keys in the dashboard, once you have accepted the Terms of Service there. A key looks like dk_live_ followed by a 16-character key id, an underscore and a 48-character secret:
dk_live_<16-character key id>_<48-character secret>
The dashboard shows the key once, when you create it; afterwards it shows only the prefix (dk_live_ plus the key id), which is safe to log. We keep only a one-way hash of the secret, so a lost key cannot be recovered: revoke it and create another.
Send the key in the Authorization header of every request. This one lists your task models and costs nothing:
import os
import requests
response = requests.get('https://dydema--eegapi-gateway.modal.run/v1/task-models', headers={"Authorization": f"Bearer {os.environ['DYDEMA_API_KEY']}"}, timeout=30)
response.raise_for_status()
print(response.json())// Node 22 or newer. Save as example.mjs and run: node example.mjs
const key = process.env.DYDEMA_API_KEY;
if (!key) throw new Error("set DYDEMA_API_KEY first");
const response = await fetch('https://dydema--eegapi-gateway.modal.run/v1/task-models', { headers: { Authorization: `Bearer ${key}` }, signal: AbortSignal.timeout(30_000) });
if (!response.ok) {
const error = await response.json();
console.error(`${response.status} ${error.code}: ${error.message}`, error.alternatives);
process.exit(1);
}
console.log(await response.json());curl -sS https://dydema--eegapi-gateway.modal.run/v1/task-models -H "Authorization: Bearer $DYDEMA_API_KEY"What a key can do
Keys created in the dashboard can call:
| Endpoint | Permission |
|---|---|
/v1/task-models (create, predict, list, expire, delete) | predictions |
GET /v1/task-models | models:read |
GET /v1/usage | usage:read |
That is the whole public API: Wizard’s task models, and your usage. A key without the permission an endpoint needs gets 403 SCOPE_MISSING.
One account, shared limits
Rate limits and spending caps belong to your account, not to a key: all your keys share them, and revoking a key does not reset them. See Errors & limits.
Replacing a key
Revoking takes effect on the next request. To swap keys without downtime, create the new key, deploy it, then revoke the old one; both work in between.
Authentication errors
| Code | Status | Meaning |
|---|---|---|
UNAUTHENTICATED | 401 | No key, a malformed key, or one the API does not recognize. |
KEY_REVOKED | 401 | The key was revoked. |
KEY_EXPIRED | 401 | The key passed its expiry date. |
SCOPE_MISSING | 403 | The key lacks the permission this endpoint needs. |
TENANT_SUSPENDED | 403 | The account is paused, usually after a failed payment. Update your card under Billing. |
IP_NOT_ALLOWED | 403 | The key is restricted to other IP addresses. |