Skip to main content
Home›Docs›API Reference›Authentication
API Reference

Authentication

Authenticate Perceive8 API requests with API keys, user JWTs, or WebSocket token parameters.

Authentication

Perceive8 supports two authentication methods for REST requests, plus a query-parameter fallback for WebSocket and SSE connections.

API key (server-side)

API keys are the recommended method for server-to-server integrations. Pass the key in the X-API-Key header:

GET /v1/analyses HTTP/1.1
Host: api.perceive8.com
X-API-Key: pk_live_xxxxxxxxxxxx

Create and revoke keys in the dashboard under Audio → Settings → Developer or via POST /v1/keys. Keys starting with pk_live_ are production keys; pk_test_ keys are used for development.

Bearer token (user-scoped)

For browser or mobile calls on behalf of a signed-in user, pass a Supabase JWT in the Authorization header:

GET /v1/analyses HTTP/1.1
Host: api.perceive8.com
Authorization: Bearer <supabase-jwt>

User-scoped requests are limited to resources the user owns or has workspace access to.

WebSocket and SSE

WebSocket and SSE endpoints cannot send custom headers from the browser. Pass the API key or JWT as a token query parameter:

wss://api.perceive8.com/v1/stream?token=pk_live_xxxxxxxxxxxx

Treat these tokens as secrets. Do not expose them in client-side URLs unless the connection is over TLS.

Forbidden and unauthorized errors

  • 401 Unauthorized — the request is missing credentials or the token has expired.
  • 403 Forbidden — the credentials are valid but the user or key does not have permission for the resource.

Rotating compromised keys

If a key is exposed, revoke it immediately in the dashboard and create a new one. Webhook secrets can be rotated by deleting the old webhook and creating a new one.