API reference

Authentication

Authenticate every request with an API key passed as a bearer token. Keys are bound to a single tenant, and all reads and writes are scoped to that tenant.

Bearer API key#

Pass your API key in the Authorization header as a bearer token. Every endpoint requires it except GET /v1/health.

bash
curl https://api.lirovo.ai/v1/jobs \
  -H "Authorization: Bearer $LIROVO_API_KEY"

Missing or invalid credentials return 401 with the error code MISSING_AUTHORIZATION (no header at all) or INVALID_API_KEY (the key does not exist, is revoked, or is malformed). A tenant whose status is not active returns 403 TENANT_SUSPENDED.

Hashed storage#

Keys are stored only as a one-way hash. The plaintext secret is shown once, in the 201 response of POST /v1/api-keys (or POST /v1/admin/tenants for the initial key), and is never returned again. Later reads expose only a short prefix for identification.

Treat keys as secrets
Capture the plaintext secret from the creation response right away. There is no way to recover it later: rotate by minting a new key and revoking the old one.

Revocation#

Revoke a key with DELETE /v1/api-keys/{id}. Revocation is idempotent and takes effect immediately: a revoked key fails authentication with 401 INVALID_API_KEY. You cannot revoke the key used to authenticate the current request (a footgun guard that returns 400). See the API keys page for the full key-management surface.

Request IDs#

Every response (success or error) carries an x-lirovo-request-id header. The same value appears as request_id inside the error envelope and in every server log line for that request. Quote it when contacting support so the request can be found in Logpush and Sentry.