Platform

Authentication

Every API is reached through the gateway at https://internal.audiclabs.com/v1/{service}/{endpoint} with an access token.

Access tokens

Create tokens in the console under API keys. A token looks like mw_live_ followed by 32 characters and is shown once; only a hash is stored, so a lost token is replaced, not recovered. Keep tokens on your server, never in browser or mobile code.

Sending the token

Use either header. They are equivalent.

Authorization: Bearer mw_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Scopes

Each token carries scopes that decide what it can call:

ScopeAllows
*Every published API.
noise-suppressor:*Every Noise Suppressor endpoint.
noise-suppressor:denoiseOnly POST /denoise.
noise-suppressor:denoise-batchOnly POST /denoise/batch.
Give each integration the narrowest scope it needs, and one token per integration, so you can revoke one without breaking the others.

A missing, unknown, revoked or expired token returns 401; a valid token without the scope returns 403. See Errors.