CLOUD

API reference

Authenticate and call the NXT API.

## Base URL
All endpoints live under /api/v1 on the NXT CLOUD domain. The machine-readable description is at /api/v1/openapi.json.

## Authentication
Create an API key in API keys and send it as a bearer token:

Authorization: Bearer nxt_live_…

Keys are shown once. Give each key only the scopes it needs. Keys can expire and be rotated: rotating creates a new key and keeps the old one working for 24 hours.

## Scopes
- account:read — organization profile
- usage:read — usage and quota information
- entitlements:read — plans and entitlements
- notifications:write — notify organization members
- files:read / files:write — files
- webhooks:manage — webhook endpoints
- ai:invoke — NXT AI (metered)

## Errors
Errors are JSON: {"error": {"code", "message", "request_id", "error_id"}}. Quote the request ID when contacting support.

## Rate limits
Each key has its own per-minute limit (60 by default). When exceeded you get 429 with a Retry-After header.

## Endpoints
- GET /api/v1/me — the organization the key belongs to and its scopes (scope: account:read)
- GET /api/v1/usage?product=ai — usage and limits for a product (scope: usage:read)
- GET /api/v1/entitlements?product=ai — whether the workspace has an active subscription or grant ("active"), tier, features and limits (scope: entitlements:read)
- GET /api/v1/plans — public plans (no authentication)
- GET /api/v1/health — service health (no authentication)

## App sign-in (first-party apps)
NXT's own iOS, Android and Windows apps use POST /api/v1/auth/token and POST /api/v1/auth/refresh with short-lived access tokens and rotating refresh tokens. These endpoints are for NXT apps only.

↑↓ navigate↵ openEsc close