Make your first API call
Create a scoped key, discover your workspace, and run an authorized operation.
Create an access key
Open Account → API, choose the personal or organization workspaces you manage, and enable the REST transport. Select only the scopes and Tool operations your integration needs. The secret appears once; store it in your script's secret manager or environment.
Use a dedicated key for each application so you can rotate or revoke one integration independently. Expiration is optional. Key controls also support IP ranges and financial budgets.
Select a workspace
Set the secret and one authorized workspace identifier in your local environment. Keep these values out of source control and browser bundles.
export NDNCI_KEY='<your-secret-key>'
export NDNCI_WORKSPACE='<authorized-workspace-uuid>'
curl --fail-with-body 'https://api.ndnci.com/v1/workspaces' \
-H "Authorization: Bearer $NDNCI_KEY" \
-H "X-Ndnci-Workspace: $NDNCI_WORKSPACE"X-Ndnci-Workspace must name a workspace explicitly included in the key. Changing this header cannot grant access to another workspace.
Discover operations
curl --fail-with-body 'https://api.ndnci.com/v1/tools' \
-H "Authorization: Bearer $NDNCI_KEY" \
-H "X-Ndnci-Workspace: $NDNCI_WORKSPACE"The response lists permitted operations, their validated inputs and whether execution is asynchronous. Use the stable operation identifier; internal workflow coordinates and provider credentials are not integration inputs.
Run an operation
This example retrieves metadata from a public web page. Keep the same idempotency key if you retry the same request after a network failure.
curl --fail-with-body 'https://api.ndnci.com/v1/runs' \
-H "Authorization: Bearer $NDNCI_KEY" \
-H "X-Ndnci-Workspace: $NDNCI_WORKSPACE" \
-H 'Idempotency-Key: 123e4567-e89b-42d3-a456-426614174010' \
-H 'Content-Type: application/json' \
--data '{"operationId":"link.preview","input":{"url":"https://example.org"}}'An immediate result returns HTTP 200 with data.kind: "result". Queued work returns HTTP 202 with data.kind: "job" and a jobId. Follow a job to obtain its result and any generated media.
Inspect usage and budget limits and honor Retry-After when a call returns HTTP 429.