Marble 2 beta

Authentication

The Marble platform and the Marble 2 Developer API use different credentials.

  • Your Clerk session authenticates the person using the platform and these docs.
  • A project-scoped World Labs API key authenticates software calling the Developer API.

Do not send a Clerk token to the Developer API, and do not use an API key as a platform login.

Send the API key

Send the secret in the WLT-Api-Key header on every protected request:

bash
curl "$WLT_API_BASE_URL/assets?pageSize=20" \  --header "WLT-Api-Key: $WLT_API_KEY"

The API does not accept the key in a query parameter.

Project binding

Every key is issued inside one project. The server derives both the account and project from the key, which is why Developer API routes do not require either identifier:

text
POST /api/v2/tasks:images2PosedRGBDGET  /api/v2/operations/{operation}GET  /api/v2/assets/{asset}

A key cannot read assets or operations owned by another project. Create a separate key when a workload needs a different project boundary.

Scopes

ScopeAllows
tasks.createSubmit an enabled task
operations.readGet, list, wait for, or trace operations
operations.cancelRequest cancellation
assets.createCreate assets and run the upload lifecycle
assets.readGet, list, and mint read URLs for assets
assets.deleteSoft-delete assets
projects.readRead the key's project where supported

Grant only what a service needs. A valid key without the required scope receives 403. Task availability is a separate beta entitlement; a key with tasks.create can still receive 404 for a task that is not enabled on its account.

Beta task access

Beta membership belongs to an account and covers its members and project API keys. It grants access to current and newly released Beta tasks. A task-specific access override can explicitly allow or deny a task; an explicit deny takes precedence over Beta membership.

Removing membership removes inherited access. Individually granted tasks can remain available. Membership does not change API-key scopes, billing, or project boundaries.

Rotate secrets without downtime

  1. Create a replacement key with the required scopes.
  2. Store and deploy the new secret.
  3. Verify an authenticated request.
  4. Revoke the old key in Developers.

Revocation is irreversible. The platform retains key metadata and the last four characters, but never returns the full secret again.