GET /openapi.json carries a Bearer token: an API key, or the session token of a person signed in to the NextIntent console.
API keys
- Created in the console (or with
POST /keysfrom a console session). The token is shown once. - Account-wide or site-bound. A bound key sees only its website: it cannot list other websites, and cannot create or delete websites.
- Scopes:
sites:read,sites:write,facts:read,facts:write. A request outside the key’s scopes answers 403. - Role:
vieweroradmin. Keys cannot mint or revoke keys whatever their role; only a person can. - Expiry: optional
expires_at. An expired key answers 401. - Revoke with
DELETE /keys/{key_id}; the key stops at once.
Console sessions
A person signed in to the console sends their session token the same way. Sessions are account-wide and are the only way to manage keys.Rate limits
600 requests a minute per key (or per console user). 60 a minute per IP before the token is checked, so a credential-stuffing loop is refused cheaply. Both answer 429 with aRetry-After header.
Tenancy
Every website belongs to an account. A site id from another account answers 404 on every route, including the views, so a publicsite_id seen in a page’s HTML gives a caller nothing.
Storefront routes are different
The routes onsdk.nextintent.ai (settings, cart, card, checkout) are called by anonymous visitors’ browsers and are gated by the page’s Origin against the site’s allowed list, not by a key. The order, refund and erase feeds carry the site’s public key in X-NextIntent-Token. See Commerce endpoints.
