Authentication

All requests require a Bearer token:

Authorization: Bearer <api-key>

API keys are organization-scoped and carry explicit permission scopes:

ScopePermissionGrants Access To
scoringreadView guidelines, criteria, scorecards, scores
scoringread_writeSubmit media for scoring + all scoring:read access
aperturereadRetrieve Creative Tags job status and results
apertureread_writeSubmit assets for tagging + all aperture:read access

A few endpoints require a valid API key but no specific scope: GET /v1/organization, GET /v1/permission,GET /v1/workspaces.

Inspect your own key with GET /v1/permission:

{
  "status": "OK",
  "result": {
    "apiKey": {
      "name": "Paulo's tests",
      "expirationDate": "2034-11-13",
      "organizationName": "Vidmob",
      "scope": [
        { "scope": "aperture", "permission": "read_write" },
        { "scope": "scoring",  "permission": "read_write" }
      ]
    }
  }
}

Authorization is enforced per workspace, not just per organization. A valid key requesting a scorecard in a
workspace it cannot reach returns 401 with "Invalid credentials for action", which is distinct from a 404
for an id that does not exist. Use that difference when debugging: 404 means no such scorecard anywhere,401 means it exists but is not yours.

API keys are managed inside the Vidmob platform (Admin Settings). Per-organization throttling applies to all endpoints. Observed headers on every response: x-ratelimit-limit: 100, x-ratelimit-remaining,x-ratelimit-reset: 60 — that is 100 requests per 60 seconds. Exceeding it returns HTTP 429.


Did this page help you?