Authentication
All protected Gradii API endpoints use HTTP bearer authentication.
Keep tokens out of client-side code, public repositories, screenshots, and support tickets. Rotate tokens when an integration owner changes or a credential may have been exposed.
Token format
Gradii API tokens use the iai_ prefix.
Error responses
Authentication failures return standard JSON error payloads with a machine-readable code.