Montek Developers

Authentication

Invitation-only accounts, projects, and API keys and how to keep them safe.

Every request carries an API key of a project as a bearer token. GET /v1/me returns the key, its project and organization, the webhook secret and the plans:

curl https://api.montek.io/v1/me -H "Authorization: Bearer $MONTEK_API_KEY"

Organizations and projects

Accounts are by invitation only, with no self sign-up and no password. Montek invites a partner, who signs in with Google on the invited address and creates their organization; the organization then invites its members.

An organization is your company: its members, roles and invoice details, in Settings. It holds one project per end customer, and API keys, plans, usage and limits belong to a project. The dashboard's project switcher chooses which one you work in.

The owner can do everything. Other roles are defined by each organization in Settings → Roles; a new organization starts with admin, sales, billing and developer. A member works in the projects they are given.

API keys

Keys start with mk_live_ and return the model's real reading. Each call counts toward the project's plan for the model; a project without one answers 402 no_plan, and a suspended project answers 403 project_suspended.

Keys belong to the project, not to a person: they keep working when the member who made them leaves. Members whose role allows it create and revoke keys on API keys; a key is shown once, and Montek stores only its SHA-256 hash.

Scopes

A key may call only what its scopes allow: extract (POST /v1/extract), cad (POST /v1/cad, GET /v1/cad/{id}) and usage (GET /v1/usage). A call outside them answers 403 forbidden.

Keeping keys safe

  • Keep keys on your server, in environment variables or a secret manager. Never ship a key to a browser or a mobile app.
  • Use one key per system, so you can revoke one without touching the others.
  • Revoking takes effect at once. If a key leaks, revoke it and create a new one.