Authentication
Every endpoint except /v1/health requires an API key.
The header
X-API-Key: kn_live_...
Keys are verified by SHA-256 hash against the key registry. The raw key is never stored, only its hash and a prefix.
Key prefixes
| kn_live_ | Production key. |
| kn_test_ | Test key, same endpoints, for development. |
Scopes and limits
- Each key carries scopes (for example
read) and a per-minute rate limit. - A key can be revoked at any time, and revocation is immediate.
- Every request is metered per key: endpoint, units and timestamp.
Never ship a key in client-side code or a public repository. Call the API from your server and keep the key in an environment variable.
Failures
# missing header
401 {"detail":"missing X-API-Key header"}
# unknown or revoked key
401 {"detail":"invalid API key"}