Authentication
Authenticate API requests with a key in the X-API-Key header. How to create, rotate and revoke keys, and why keys belong on a server.
Every request to /v1/recognize carries an API key. Requests without one get 401.
Create a key
Sign in to the account page and create a key. The full key is shown once, right after you create it. We store only a hash, so a lost key cannot be recovered: create a new one and revoke the old one.
- Keys start with
cf_live_. - You can have up to 10 active keys, for example one per environment.
- Quota belongs to your account, not to a key. Extra keys add no capacity.
Send the key
Put it in the X-API-Key header. A bearer token works too.
# Header (preferred)
curl https://api.chessglance.com/v1/recognize -H "X-API-Key: $API_KEY" -F image=@board.png
# Or as a bearer token
curl https://api.chessglance.com/v1/recognize -H "Authorization: Bearer $API_KEY" -F image=@board.png// Server side only: never ship a key to a browser.
const headers = { 'X-API-Key': process.env.API_KEY };headers = {"X-API-Key": os.environ["API_KEY"]}Keep keys on a server
The API accepts requests from any origin so you can test from a browser console, but a key in front-end code is a key anyone can copy. Call the API from your backend, and give the browser your own endpoint. If a key leaks, revoke it on the account page; revocation takes effect within about 30 seconds.
Errors
| Status | Meaning |
|---|---|
401 |
No key sent, or the key is invalid or revoked. The body says which. |
429 |
The monthly quota is used up, or you are over the per-minute request limit. See errors and limits. |
Plans
Your plan decides the monthly quota: 500 requests on API Free, 10,000 on Starter, 100,000 on Growth, 1,000,000 on Scale. See the pricing page.