Docs
On this page
Docs/AVM/Authentication

Build · AVM

Authentication

Every request requires a Valtaic API key associated with an active customer account and authorised for the requested operation.

Authenticate a Request

Recommended header:

http
Authorization: Bearer vlt_live_...

Alternative header:

http
X-API-Key: vlt_live_...

Use one method per request.

Credential Safety

  • Store keys in a server-side secret manager.
  • Never embed a live key in browser or mobile application code.
  • Redact authentication headers from logs and error tracking.
  • Use separate credentials for development, staging and production.
  • Issue separate keys to independent systems.
  • Rotate immediately after suspected exposure.

Do not expose a live key in browser or mobile code. Route client requests through a trusted backend, which then calls Valtaic.

Environments

Keys carry an environment prefix:

text
vlt_live_...
vlt_test_...

The assigned plan and scopes remain authoritative. A vlt_test_ prefix does not, by itself, select a free sandbox or different service. Use the environment and usage terms agreed for your account.

Scopes

ScopeAccess
avm:valueExisting-property valuation, batch, metadata and enabled job endpoints
avm:developmentIndividual and batch development-valuation endpoints
avm:stored-dataPermission to set options.use_stored_data=true on supported endpoints

Submitting a development job requires both avm:value and avm:development. The dedicated synchronous development routes require avm:development.

Effective access is limited by both the key and its associated plan. A request outside those permissions returns 403 insufficient_scope.

The presence of a scope does not enable a capability that is absent from GET /v3/releases/current.

Plan Controls

A plan can define:

  • request rate and burst;
  • HTTP requests per month;
  • valuation units per month;
  • maximum synchronous batch rows;
  • maximum asynchronous job rows;
  • maximum concurrent in-flight requests;
  • available scopes.

A valuation unit is one property row:

CallUnits
Single value1
500-row batch500
2,500-row job2,500

The service supports up to 2,500 synchronous rows or 2,500 job rows. Read the active limits from GET /v3/releases/current; your plan and the request-body limit may impose lower limits. Retrying an identical job with the same valid idempotency_key does not reserve its valuation units again.

Authorisation and Limits

Before processing a request, Valtaic validates the key, confirms that its plan is active and checks the required scope. Rate, quota, batch-size and concurrency limits are then applied according to that plan. See Limits and Safeguards for payload, capacity and processing controls that apply alongside plan limits.

Authentication and Limit Errors

StatusConditionAction
401Missing or invalid keySupply an active credential.
403insufficient_scopeUse an authorised key/plan.
413plan_batch_limit_exceededSplit work or use an approved larger limit.
429monthly_valuation_quota_exceededWait for reset or change plan.
429tenant_concurrency_limit_exceededRespect Retry-After and retry with jitter.
503Authentication or request admission temporarily unavailableRetry with bounded backoff.

Zero-Downtime Rotation

  1. Issue a second key for the same tenant and plan.
  2. Store it in the consuming system's secret manager.
  3. Deploy the consuming system with the replacement.
  4. Confirm successful usage.
  5. Revoke the old key.