Skip to content
Chessglance
Open app
Menu
b1 — Authentication

Authentication

Authenticate API requests with a key in the X-API-Key header. How to create, rotate and revoke keys, and why keys belong on a server.

Every request to /v1/recognize carries an API key. Requests without one get 401.

Create a key

Sign in to the account page and create a key. The full key is shown once, right after you create it. We store only a hash, so a lost key cannot be recovered: create a new one and revoke the old one.

  • Keys start with cf_live_.
  • You can have up to 10 active keys, for example one per environment.
  • Quota belongs to your account, not to a key. Extra keys add no capacity.

Send the key

Put it in the X-API-Key header. A bearer token works too.

Authenticate
# Header (preferred)
curl https://api.chessglance.com/v1/recognize -H "X-API-Key: $API_KEY" -F image=@board.png

# Or as a bearer token
curl https://api.chessglance.com/v1/recognize -H "Authorization: Bearer $API_KEY" -F image=@board.png

Keep keys on a server

The API accepts requests from any origin so you can test from a browser console, but a key in front-end code is a key anyone can copy. Call the API from your backend, and give the browser your own endpoint. If a key leaks, revoke it on the account page; revocation takes effect within about 30 seconds.

Errors

Status Meaning
401 No key sent, or the key is invalid or revoked. The body says which.
429 The monthly quota is used up, or you are over the per-minute request limit. See errors and limits.

Plans

Your plan decides the monthly quota: 500 requests on API Free, 10,000 on Starter, 100,000 on Growth, 1,000,000 on Scale. See the pricing page.