BEFOREAI / DEVELOPER DOCUMENTATIONGood experiences start with good foundations.
Start here / Authentication

Keep the key backstage.

Authenticate from your backend and let your frontend focus on the experience.

Your connection details

BeforeAI supplies your API key and gateway URL during onboarding. Use the assigned URL as the base for the paths in these guides.

Request headers
X-API-Key: YOUR_API_KEY
Content-Type: application/json
Accept: application/json

Use Content-Type for JSON request bodies. The same X-API-Key authenticates a try-on submission and its status requests.

Call from your server

Store credentials in your hosting provider’s secret configuration or server environment. Never ship the key in browser code, mobile app bundles, public repositories, or URLs.

Authenticate customers in your own application and validate their requests before your backend calls the gateway. Your account key is not a customer login token.

Catalog preparation is a separate permission boundary.

BeforeAI prepares structured product attributes during onboarding. Arrange catalog preparation and permissions with the team before submitting recommendations.

Image access

Image operations accept HTTPS image URLs in JSON, rather than uploaded files or Base64 strings. Upload images to your own storage before requesting a generation.

Signed URLs can be used if the service can fetch them and they remain valid throughout queuing and processing. Keep input URLs available until a job reaches completed or failed.

Set your own photo-consent, storage-access, and deletion policies. Avoid recording customer photos or signed URLs in application logs.

Credential maintenance

If a key is exposed, contact BeforeAI to revoke or replace it and update your server configuration. Do not copy live keys into troubleshooting tickets. Review error handling for rejected requests.