Authentication
All requests require a Bearer token:
Authorization: Bearer <api-key>
API keys are organization-scoped and carry explicit permission scopes:
| Scope | Permission | Grants Access To |
|---|---|---|
scoring | read | View guidelines, criteria, scorecards, scores |
scoring | read_write | Submit media for scoring + all scoring:read access |
aperture | read | Retrieve Creative Tags job status and results |
aperture | read_write | Submit assets for tagging + all aperture:read access |
A few endpoints require a valid API key but no specific scope: GET /v1/organization, GET /v1/permission,GET /v1/workspaces.
Inspect your own key with GET /v1/permission:
{
"status": "OK",
"result": {
"apiKey": {
"name": "Paulo's tests",
"expirationDate": "2034-11-13",
"organizationName": "Vidmob",
"scope": [
{ "scope": "aperture", "permission": "read_write" },
{ "scope": "scoring", "permission": "read_write" }
]
}
}
}Authorization is enforced per workspace, not just per organization. A valid key requesting a scorecard in a
workspace it cannot reach returns 401 with "Invalid credentials for action", which is distinct from a 404
for an id that does not exist. Use that difference when debugging: 404 means no such scorecard anywhere,401 means it exists but is not yours.
API keys are managed inside the Vidmob platform (Admin Settings). Per-organization throttling applies to all endpoints. Observed headers on every response: x-ratelimit-limit: 100, x-ratelimit-remaining,x-ratelimit-reset: 60 — that is 100 requests per 60 seconds. Exceeding it returns HTTP 429.
Updated about 1 month ago