Authentication
Every request carries an API key in the x-api-key header. Keys belong to your account: clips, voices and transcripts made with any of your keys land in the same library you see in Studio.
Sending the key
cURL
curl https://api.voixa.vovix.io/v1/account \
-H "x-api-key: $VOIXA_API_KEY"
Only GET /health and GET / answer without a key. Everything else — including the list of voices and samples — needs one, so keep keys on your server. If you show Voixa voices in your own app, call GET /samples from your backend and pass the sample URLs to the browser.
Creating and rotating keys
Create keys in Studio → API keys. Make one key per app: when you rotate, create the new key, switch the app to it, then delete the old one — there is no downtime.
A new key needs two to three minutes before the gateway accepts it. Until then calls answer {"message":"Forbidden"} from the gateway itself.
Managing keys (GET /keys, POST /keys, DELETE /keys/{keyId}) is only possible from a signed-in Studio session, never with a key: a leaked key cannot mint more keys.
What a key is allowed
Each key has a request rate and a daily number of calls (see Limits). The allowance for characters of speech and seconds of transcription belongs to your account, shared by all your keys and Studio. GET /account shows both.
Clips carry source: "api" when made with a key and source: "studio" when made in Studio, so you can list them separately.