Integrate / Access & errors
Access, errors, and privacy
Public deterministic requests work without model credentials. Account and provider operations have separate access rules.
Discover the current host#
GET /v1 reports configured semantic capabilities. GET /api/account reports whether accounts, email delivery, and billing are available. Check these before rendering controls that depend on optional services.
Use the right credential#
Browser account actions use a same-origin session. Server integrations may use a Bearer API key with the required scope. Sense inference uses sense-inference; model-assisted argument analysis uses argument-analysis; observation contribution uses contribute.
Keep provider keys and operator API keys out of frontend bundles, URLs, analytics, and logs. Do not reuse a token belonging to another product or account.
Handle failures intentionally#
| Status | Action |
|---|---|
| 400 | Fix the input; show the returned validation message |
| 401 / 403 | Request sign-in or the correct entitlement; do not retry blindly |
| 404 | The requested record or release does not exist |
| 409 | Resolve a state conflict, such as changing a submitted answer |
| 410 | Stop using a withdrawn release |
| 429 | Back off and let the user know the limit was reached |
| 503 | The required service is unavailable on this host |
Network errors and cancellation may occur before an HTTP response. Keep those distinct from validation errors.
Consent before external processing#
Jev argument analysis needs consent: true. Transcription requires a separate explicit send. Deterministic local service calls do not authorize publication or contribution of a private passage.
Next: Observation permissions and the privacy policy.