Authentication
The Hydrilla AI API uses secure Bearer tokens to authenticate requests. Manage your keys and monitor usage through the developer dashboard.
Authorization Headers
Pass your secret API key in the Authorization header using standard Bearer authentication:
curl -X GET https://api.hydrilla.co/v1/user/me \
-H "Authorization: Bearer hyd_live_d81a9f02b37c4e91823abce"Alternatively, you can provide it via the x-api-key header:
curl -X GET https://api.hydrilla.co/v1/user/me \
-H "x-api-key: hyd_live_d81a9f02b37c4e91823abce"Key Security & Hashing
One-Time Reveal: When you generate a key, the full key (hyd_live_...) is displayed once. Make sure to store it securely in your environment variables.
SHA-256 Hashing: Hydrilla never stores your plaintext API key in the database. Only a cryptographic SHA-256 hash is persisted.
Instant Revocation: You can revoke an API key at any time in the dashboard under API Keys. Revocation is instantaneous.
Error Codes
401 Unauthorized
Returned if the key is missing, malformed, or has been revoked.
{
"error": "Unauthorized",
"message": "Invalid or revoked API key. Generate a key at https://hydrilla.co/app/api-keys"
}402 Insufficient Credits
Returned if your account credit balance is too low to perform the generation.
{
"error": "Insufficient credits",
"message": "This operation requires 2 credits, but your balance is 0.",
"credits_available": 0,
"credits_required": 2,
"upgrade_url": "https://hydrilla.co/app/settings"
}