NDNCI Docs
API v1

Keys and workspace permissions

Limit each integration's transports, operations, workspaces, IP ranges and spending.

Explicit workspace access

A key may include several workspaces. You can select your personal workspace and organizations where you are currently an owner or administrator. Membership alone does not grant access-management authority.

Each REST request uses X-Ndnci-Workspace to choose one permitted workspace. MCP operations select the workspace in their validated input. NDNCI checks the user's current rights on every operation, so removing organization rights also removes the authority carried by existing grants.

Scopes and Tool operations

Scopes describe the resources an integration may use. You can further restrict a key to an explicit Tool-operation allowlist. A read scope does not authorize execution or uploads.

ScopePermission
workspaces:readDiscover authorized workspaces
tools:readDiscover authorized Tool operations
tools:runEstimate and run permitted operations
jobs:readRead job status and output
jobs:writeCancel or retry eligible jobs
queue:readRead workspace queue capacity
billing:readRead credit balances and transactions
media:readList media and obtain download URLs
media:writeUpload workspace media
usage:readRead usage counters and budgets
events:readRead authorized workspace events
webhooks:readRead events and webhook deliveries
webhooks:writeManage verified webhook destinations and replay delivery

Choose REST, MCP, or both when creating a key. A REST-only key cannot authenticate to MCP, and an MCP-only key cannot call REST routes. Create separate keys when the integrations need independent rotation, attribution or budgets.

Optional expiration and IP restrictions

Expiration is optional. A key without an expiration remains usable until revoked, suspended, or deprived of the required workspace rights.

An IP allowlist accepts IPv4 and IPv6 addresses or CIDR ranges. Use the public egress address of the application making the call. An empty allowlist permits any source IP; it does not bypass scopes or other controls.

Rotate and revoke

Copy a new secret when you rotate a key, update the application's secret store, and verify its next authorized request. The previous secret stops authenticating. NDNCI stores a hash of key secrets and never returns an existing secret.

Revocation stops new authenticated operations. A provider request already accepted before revocation can still incur its committed cost; job cancellation explains the financial boundary.

Key creation, rotation, revocation and security suspension produce bounded account notifications. Repeated reads do not generate an email for each request.

Set key and workspace budgets to limit unattended spending.

On this page