Marble 2 beta
Authentication
The Marble platform and the Marble 2 Developer API use different credentials.
- Your Clerk session authenticates the person using the platform and these docs.
- A project-scoped World Labs API key authenticates software calling the Developer API.
Do not send a Clerk token to the Developer API, and do not use an API key as a platform login.
Send the API key
Send the secret in the WLT-Api-Key header on every protected request:
The API does not accept the key in a query parameter.
Project binding
Every key is issued inside one project. The server derives both the account and project from the key, which is why Developer API routes do not require either identifier:
A key cannot read assets or operations owned by another project. Create a separate key when a workload needs a different project boundary.
Scopes
| Scope | Allows |
|---|---|
tasks.create | Submit an enabled task |
operations.read | Get, list, wait for, or trace operations |
operations.cancel | Request cancellation |
assets.create | Create assets and run the upload lifecycle |
assets.read | Get, list, and mint read URLs for assets |
assets.delete | Soft-delete assets |
projects.read | Read the key's project where supported |
Grant only what a service needs. A valid key without the required scope receives
403. Task availability is a separate beta entitlement; a key with
tasks.create can still receive 404 for a task that is not enabled on its
account.
Beta task access
Beta membership belongs to an account and covers its members and project API keys. It grants access to current and newly released Beta tasks. A task-specific access override can explicitly allow or deny a task; an explicit deny takes precedence over Beta membership.
Removing membership removes inherited access. Individually granted tasks can remain available. Membership does not change API-key scopes, billing, or project boundaries.
Rotate secrets without downtime
- Create a replacement key with the required scopes.
- Store and deploy the new secret.
- Verify an authenticated request.
- Revoke the old key in Developers.
Revocation is irreversible. The platform retains key metadata and the last four characters, but never returns the full secret again.