View as Markdown

API

Keys and scopes

Create, scope, inspect, and revoke API keys.

Keys belong to a workspace. Workspace owners and admins create and revoke them in the console. Members can see the prefix, name, and usage of each key.

Scopes

Each key carries one or both scopes:

scopegrants
papers/v1/search and /v1/resolve
pdfNo public endpoint uses this scope today.

Calling an endpoint outside the key's scopes answers 403 InsufficientScope. Pick the smallest set the integration needs.

Inspect the current key

curl https://api.anara.com/v1/keys/current \
  -H "Authorization: Bearer $ANARA_API_KEY"
Response
{ "id": "k_…", "name": "prod", "keyPrefix": "ana_live_Ab12", "scopes": ["papers"], "workspaceId": "…", "createdAt": "…", "revokedAt": null }

Revoke

Revoke in the console, or let the key revoke itself, for example from an incident runbook:

curl -X POST https://api.anara.com/v1/keys/current/revoke \
  -H "Authorization: Bearer $ANARA_API_KEY"

Revocation takes effect at once. Every later request with that key answers 401 with the message API key revoked.