Skip to main content
Every request except GET /openapi.json carries a Bearer token: an API key, or the session token of a person signed in to the NextIntent console.

API keys

  • Created in the console (or with POST /keys from a console session). The token is shown once.
  • Account-wide or site-bound. A bound key sees only its website: it cannot list other websites, and cannot create or delete websites.
  • Scopes: sites:read, sites:write, facts:read, facts:write. A request outside the key’s scopes answers 403.
  • Role: viewer or admin. Keys cannot mint or revoke keys whatever their role; only a person can.
  • Expiry: optional expires_at. An expired key answers 401.
  • Revoke with DELETE /keys/{key_id}; the key stops at once.

Console sessions

A person signed in to the console sends their session token the same way. Sessions are account-wide and are the only way to manage keys.

Rate limits

600 requests a minute per key (or per console user). 60 a minute per IP before the token is checked, so a credential-stuffing loop is refused cheaply. Both answer 429 with a Retry-After header.

Tenancy

Every website belongs to an account. A site id from another account answers 404 on every route, including the views, so a public site_id seen in a page’s HTML gives a caller nothing.

Storefront routes are different

The routes on sdk.nextintent.ai (settings, cart, card, checkout) are called by anonymous visitors’ browsers and are gated by the page’s Origin against the site’s allowed list, not by a key. The order, refund and erase feeds carry the site’s public key in X-NextIntent-Token. See Commerce endpoints.