Integrate / Access & errors

Access, errors, and privacy

Public deterministic requests work without model credentials. Account and provider operations have separate access rules.

Discover the current host#

GET /v1 reports configured semantic capabilities. GET /api/account reports whether accounts, email delivery, and billing are available. Check these before rendering controls that depend on optional services.

Use the right credential#

Browser account actions use a same-origin session. Server integrations may use a Bearer API key with the required scope. Sense inference uses sense-inference; model-assisted argument analysis uses argument-analysis; observation contribution uses contribute.

Keep provider keys and operator API keys out of frontend bundles, URLs, analytics, and logs. Do not reuse a token belonging to another product or account.

Handle failures intentionally#

Status Action
400 Fix the input; show the returned validation message
401 / 403 Request sign-in or the correct entitlement; do not retry blindly
404 The requested record or release does not exist
409 Resolve a state conflict, such as changing a submitted answer
410 Stop using a withdrawn release
429 Back off and let the user know the limit was reached
503 The required service is unavailable on this host

Network errors and cancellation may occur before an HTTP response. Keep those distinct from validation errors.

Jev argument analysis needs consent: true. Transcription requires a separate explicit send. Deterministic local service calls do not authorize publication or contribution of a private passage.

Next: Observation permissions and the privacy policy.