AI Glot websiteOpen AI Glot
REST APIAuthentication and scopes

Authentication and scopes

Authenticate AI Glot API requests with workspace keys or OAuth tokens, choose minimum scopes and rotate credentials without exposing secrets.

Send a workspace API key or OAuth access token as a bearer credential:

Authorization header
Authorization: Bearer aig_live_••••••••

Never place a credential in a query string. URLs are copied into logs, browser history and referrer headers.

Workspace API keys

An admin creates keys in Developer tools. The complete secret is shown once; AI Glot stores only a protected hash. Up to 10 keys may be active in a workspace.

Create an API key dialog

Create a named key and choose its scopes

Use a separate named key for each integration.

Rotating a key

The key list offers a Rotate action. It issues a replacement with the same name, scopes and expiry, then revokes the original in the same operation. The old key stops working immediately, is marked replaced rather than plainly revoked, and records which key succeeded it.

That is deliberate: you rotate because a secret may be compromised, and a key that keeps working for another hour keeps working for whoever took it. For a planned, zero-downtime handover, create a second key instead, move the integration onto it, confirm the old key is quiet, then revoke it.

OAuth tokens

The CLI and compatible MCP clients can use OAuth 2.1. OAuth is recommended for a person because the connection records who approved it and respects that member’s access ceiling. API keys remain the right fit for CI and backend services.

Scopes

These scopes work today:

ScopeAllows
account:readWorkspace identity, plan, capabilities, limits and credit summary
usage:readUsage totals and time buckets
batches:readList translations, inspect progress and download completed results
batches:createCreate a translation, plan it and approve it. Approval spends workspace credits
batches:writeRename and archive translations, and cancel one that is running. Cancelling charges for the work already completed
glossaries:readList and retrieve glossaries
glossaries:writeCreate, update, replace or delete glossaries

A missing scope returns 403 insufficient_scope.

Reserved scopes

Two more scopes can be granted today but no endpoint honours them yet. They appear on the OAuth consent screen and in the dashboard’s Full access preset, so they are documented here rather than hidden: a permission you are asked to approve should always be findable in the reference.

ScopeWill allowStatus
files:writeUpload files to the workspace as a separate step, rather than sending them with the create callNot available yet
webhooks:writeCreate, edit and delete the webhooks that notify your systems when work finishesNot available yet

They exist early so that a credential granted now keeps working the day the capability ships, without a second approval round. Read capabilities on GET /v1/account rather than the granted scopes to decide what a credential can actually do. A scope can be held before the endpoint behind it exists.

Member ceiling

Workspace admins can limit developer access for members. An OAuth client receives the intersection of what it requested and what the approving member may use. Reconnecting with a broader request cannot bypass a read-only ceiling.

batches:create is excluded from the default member ceiling. Every other scope is granted to a member’s connection out of the box; the one that spends credits is not. An agent looping with a delegated credential could otherwise consume a whole month’s allowance before anyone noticed, and credits cannot be un-spent. A workspace admin widens the ceiling deliberately when agent-initiated translation is wanted.

Use these docs with your AI tools

An AI agent can read this documentation directly. You do not need an account or an API key. Everything here is public and read-only.

Query these docs via MCP

Recommended

Add this server to Claude, Claude Code, Cursor, Mistral, or any tool that supports MCP. Your agent can then search AI Glot Docs documentation and read it in full, instead of answering from memory.

https://ai-glot.com/docs/mcp
  • searchFind the passages that answer a question.
  • fetchRead one page in full, as Markdown.
  • list_pagesSee every page in this documentation.

Query these docs over HTTP

The same tools also work as plain web requests. Use this for scripts, or for any tool that does not support MCP. There is one endpoint per tool. Arguments go in the query string, and the answer comes back as JSON.

https://ai-glot.com/docs/api/docs/search?query=custom+domain

Read the OpenAPI description. It is built from the same definitions as the tools, so it always matches what the endpoints do.

Read these docs as Markdown

Add .md to any page URL to get its Markdown source. You can also send the headerAccept: text/markdown to the page URL itself.

To read the whole documentation in one file, open llms-full.txt. For a short index of every page, open llms.txt.