Every call to /v1 carries an API key in the Authorization header, over HTTPS. No other form is accepted (neither a URL parameter nor a cookie).
GET /v1/contents HTTP/1.1
Host: api.memojin.com
Authorization: Bearer mj_live_…Key format
A key reads mj_test_ or mj_live_, followed by a secret of 32 to 64 letters and digits. Its first twelve characters (mj_live_AbCd) form its prefix: that is what we quote when we talk with you about a key.
Memojin only keeps the fingerprint (SHA-256) of the full key. It is therefore shown to you once, when it is created; if you lose it, it cannot be recovered: a new one must be created.
One organization, one account
A key belongs to an organization (your company, your school) and acts for one Memojin account, chosen when the organization is created. It sees and changes exactly what that account can see and change in the app, under the same rules: nothing more, nothing less. A resource of another account answers 404 not_found, as if it did not exist.
As in the app, most operations require that account to have an active plan; otherwise they answer 403 forbidden. An organization never changes accounts: to act for another account, ask for another organization. All the keys of an organization share its rate limits.
Test keys and live keys
| Prefix | Environment | Available | Effects |
|---|---|---|---|
mj_test_ | Sandbox | As soon as your organization is opened | Same data as the account, simulated AI generations (no credit), 100 requests a day. See sandbox. |
mj_live_ | Production | Once your organization is approved | Everything is real; generations use the account’s AI credits. |
Keep the key secret
- Call the API from your server. Keep the key in an environment variable or a secret manager, never in a code repository.
- Never in a web page or a mobile app: the API does not answer browser CORS requests, on purpose. An exposed key must be revoked.
- One key per application and per environment: if one leaks, you revoke only that one.
- Give each key the fewest scopes it needs: a dashboard only needs reads.
Rotate or revoke a key
To rotate a key without downtime: ask for a new one, deploy it, then ask us to revoke the old one. A revoked key stops working in less than a minute (keys are read again every 30 seconds at most) and then answers 401 revoked_api_key.
Today these steps go through e-mail, at contact@memojin.com; they will move to the developer space Coming soon.
Authentication errors
{
"error": {
"code": "invalid_api_key",
"message": "Missing or invalid API key: send the header `Authorization: Bearer mj_live_…` (or `mj_test_…`)."
}
}401 invalid_api_key: missing or malformed header, or unknown key.401 revoked_api_key: the key was revoked.403 live_not_enabled: a live key of an organization not yet opened for production.403 account_suspended: the organization is suspended.403 insufficient_scope: the key lacks the operation’s scope (see scopes).
The message follows the Accept-Language header (English by default); your code relies on code. See errors.