Verify an API key

GET/v1/auth/verify

Confirms that an API key works and returns the organization it belongs to. It needs no scope, which makes it the right first call from a new integration.

Headers

  • AuthorizationstringRequired

    Bearer followed by a space and your API key, for example Bearer vk_….

Response

200

  • successbooleanRequired

    Whether the API key is valid

    Example true
  • messagestringRequired

    Status message

    Example "API key is valid"
  • organization_idstringRequired

    Organization ID associated with this API key

    Example "123e4567-e89b-12d3-a456-426614174000"
  • organization_namestring or null

    Organization name

    Example "Acme Corporation"

Errors

Errors share one JSON body: success, error, message, optional details, and request_id.

StatusCodeMeaning
401UNAUTHORIZED

The Authorization header is missing or malformed, or the API key is unknown or has been deactivated.

401API_KEY_EXPIRED

The API key is past its expiry date. Create a new key in the Victoria AI app.

403ORGANIZATION_DEACTIVATED

The organization that owns this API key has been deactivated.

429RATE_LIMITED

Too many requests for this API key: more than 100 a minute to one endpoint, or 600 a minute in total. Retry after the number of seconds in the Retry-After header. See Rate limits.

500INTERNAL_ERROR

Something failed on our side. The response never includes internal details; quote its request_id when you contact support.

503UPSTREAM_TIMEOUT

A service the API depends on timed out. The request is safe to retry.

503AUTH_UNAVAILABLE

The API key couldn't be checked because the authentication service was unavailable. The request is safe to retry.

Response headers

HeaderDescription
X-Request-ID

Correlation ID for the request, also returned as request_id in error bodies. Send your own X-Request-ID, up to 128 letters, digits, ., _, : or -, and it's used instead.

RateLimit-Limit

Requests allowed to this endpoint per minute.

RateLimit-Remaining

Requests you can still send to this endpoint right now.

RateLimit-Reset

Seconds until the endpoint's full limit is available again.

Retry-After

On a 429: seconds to wait before retrying.