Authentication
Every request carries an ewpire API key as a Bearer token.
Send your key in the Authorization header of every request:
curl https://ewpire.com/api/v1/models \
-H "Authorization: Bearer $EWPIRE_API_KEY"What a key is
A key looks like ewp_live_ followed by an 8-character prefix and a 32-character secret. ewpire stores only a hash of it and the prefix, so the full key is shown once, when you create it. If you lose it, revoke it and create a new one. See API keys.
A key belongs to a workspace. Requests made with it are paid from that workspace's credit balance and appear in its usage.
When a key is refused
A missing, mistyped or revoked key gets 401 with the code invalid_api_key:
JSON
{
"error": {
"message": "Incorrect API key provided. Create or copy a key in the ewpire app under API.",
"type": "invalid_request_error",
"param": null,
"code": "invalid_api_key"
}
}Keep keys secret
- Call the API from your server, never from code that runs in a browser or ships inside an app.
- Keep keys in environment variables or a secret manager, not in your repository.
- Give each service its own key, with its own limits, so you can revoke one without touching the others.