Authentication & Headers

AVAILABLE

Naagmani authenticates API calls using Bearer tokens passed via the standard Authorization header.


Supported Token Formats #

http
Authorization: Bearer <TOKEN>
Token PrefixToken TypeTarget SurfacePermissions
nsk_live_...Project API KeyGateway Data Plane (:8080)Model Inference, Streaming, Embeddings
nst_live_...Project Service TokenGateway Data Plane (:8080)Scoped by Capability Matrix
usr_sess_...User Session TokenControl Plane API (:8081)RBAC Scoped Org & Project Management

Error Handling #

If a token is invalid, missing, or expired:

json
{
  "code": "invalid_api_key",
  "message": "The provided API key is invalid or has been revoked.",
  "request_id": "req_01J8F0A2B3C4D5E6F7G8H9J0K1"
}

Next Steps #