Hydrilla AI Logo

Authentication

The Hydrilla AI API uses secure Bearer tokens to authenticate requests. Manage your keys and monitor usage through the developer dashboard.

Authorization Headers

Pass your secret API key in the Authorization header using standard Bearer authentication:

Bearer Header (Recommended)
curl -X GET https://api.hydrilla.co/v1/user/me \
  -H "Authorization: Bearer hyd_live_d81a9f02b37c4e91823abce"

Alternatively, you can provide it via the x-api-key header:

x-api-key Header
curl -X GET https://api.hydrilla.co/v1/user/me \
  -H "x-api-key: hyd_live_d81a9f02b37c4e91823abce"

Key Security & Hashing

One-Time Reveal: When you generate a key, the full key (hyd_live_...) is displayed once. Make sure to store it securely in your environment variables.

SHA-256 Hashing: Hydrilla never stores your plaintext API key in the database. Only a cryptographic SHA-256 hash is persisted.

Instant Revocation: You can revoke an API key at any time in the dashboard under API Keys. Revocation is instantaneous.

Error Codes

401 Unauthorized

Returned if the key is missing, malformed, or has been revoked.

401_UNAUTHORIZED.json
{
  "error": "Unauthorized",
  "message": "Invalid or revoked API key. Generate a key at https://hydrilla.co/app/api-keys"
}

402 Insufficient Credits

Returned if your account credit balance is too low to perform the generation.

402_INSUFFICIENT_CREDITS.json
{
  "error": "Insufficient credits",
  "message": "This operation requires 2 credits, but your balance is 0.",
  "credits_available": 0,
  "credits_required": 2,
  "upgrade_url": "https://hydrilla.co/app/settings"
}