API keys and scopes

Every account mints its own keys, one per integration, and each key only opens the scopes you tick.

Creating a key

  1. 1

    Open Settings → API keys

    The page lists every key on the account.

  2. 2

    Name it after where it will run

    The name is only for you, e.g. n8n production. One key per integration means revoking one never takes down the others.

  3. 3

    Tick only the scopes you need

    Write scopes do not imply read. A script that lists and creates videos needs both videos:read and videos:write.

  4. 4

    Copy the key immediately

    Only a hash is stored, so the full string appears once and cannot be retrieved. Lost it? Revoke and create a new one.

Keys look like viai_sk_ followed by 43 random characters. The fixed prefix lets GitHub and GitLab secret scanners spot a key accidentally pushed to a repo.

You can set an expiry at creation time. Leave it empty for a key that never expires — it can still be revoked at any moment. An account holds at most 20 active keys.

Sending the key

X-Api-Key: viai_sk_...

Libraries that only speak bearer auth can use this instead — both are accepted:

Authorization: Bearer viai_sk_...

An API key is not a web session

Keys only open paths under /api/v1/public. Sending a key to a web-app endpoint is rejected, and a login cookie cannot call the public API.

Scope reference

ScopeOpens
videos:readList and read videos
videos:writeCreate, render and cancel videos
jobs:readRead generation job status
jobs:writeQueue a generation job
posts:writePublish a rendered video to a real channel — kept separate from videos:write because this is the step that goes public
channels:readList connected channels
credits:readRead the credit balance and transaction history
campaigns:readRead campaigns and their slots
campaigns:writeCreate, launch, pause and cancel campaigns
sources:readRead news sources and scanned items
sources:writeCreate, update and delete news sources
media:readList and read media files
media:writeUpload and delete media files
templates:readList brand templates
catalog:readVoices, music, ad templates and AI effects
analytics:readRead performance stats
usage:readRead API and MCP call history

Keeping keys safe

  • A key opens exactly what you ticked, on your account. Whoever holds the string can do that much — including spending credits.
  • Keep keys in environment variables. Never embed one in source code or in a page that runs in an end user's browser.
  • One key per integration. The list page shows last used for each key, so a key that has gone quiet is a good candidate for revocation.
  • Revocation takes effect immediately and cannot be undone. Suspect a leak? Revoke first.

Authentication errors

StatusMeansFix
401No key sent, or the key is wrong, revoked or expiredCheck the header and the key status on the management page
403Valid key, missing scope for this pathThe body names the missing scope; create a key that has it
429Calling too fastBack off and retry