Skip to content

Authentication

Intentgine uses a two-step authentication flow: exchange your API Key for a short-lived JWT, then use the JWT for all subsequent requests.

You can view and manage your API keys in the Developer Console.

Your API keys carry many privileges, so be sure to keep them secure! Do not share your secret API keys in publicly accessible areas such as GitHub, client-side code, and so forth.

Send your API key as a Bearer token to the /v1/auth endpoint:

POST /v1/auth
Authorization: Bearer sk_live_...

The response contains a short-lived JWT (expires after 1 hour):

{
"token": "eyJhbGciOiJIUzI1NiIs...",
"expires_at": "2025-01-15T13:00:00.000Z",
"app_id": "your-app-id"
}

Use the returned JWT as the Bearer token for all other API requests:

Authorization: Bearer eyJhbGciOiJIUzI1NiIs...

When the JWT expires, exchange your API key again to get a new one.

All API requests must be made over HTTPS. Calls made over plain HTTP will fail.

Terminal window
curl -X POST https://api.intentgine.dev/v1/auth \
-H "Authorization: Bearer sk_live_1234567890abcdef"
Terminal window
curl https://api.intentgine.dev/v1/banks \
-H "Authorization: Bearer eyJhbGciOiJIUzI1NiIs..."
CodeDescription
401Unauthorized. The API key or JWT is missing or invalid.
403Forbidden. The token is valid, but the App does not have permission for this action.
429Too Many Requests. Auth exchange is rate limited to 60 requests per minute per API key.