Kiket docs
API & SDKs

API & SDKs

Drive Kiket from code — REST, six language SDKs, CLI, MCP, webhooks.

Everything the web app can do is an API call. The API is the single interface; every other surface (SDKs, CLI, MCP) is a thin wrapper over it.

Base URL

https://api.kiket.dev/api/v1

Self-hosted deployments use their own domain.

Auth

Two ways to act on behalf of a human in the product, and one for machines:

  • Interactive session — Email/password or Google / GitHub OAuth on the web app; short-lived access tokens with refresh (see Sign-in and accounts).
  • API key (long-lived, scoped) — what SDKs, CLI, and automation use when there is no browser.

Create an API key in Settings → API Keys. Pass it as a Bearer header:

curl -H "Authorization: Bearer $KIKET_API_KEY" https://api.kiket.dev/api/v1/platform/cases

Shape

  • REST, resource-oriented, JSON bodies.
  • Versioned in the URL (/api/v1).
  • Cursor paginated on collections (?cursor=<opaque>&limit=50).
  • Idempotent on writes via Idempotency-Key header.
  • RFC 7807 error bodies ({ "type": "...", "title": "...", "status": 422 }).

Live reference

An OpenAPI spec lives at api.kiket.dev/api/v1/docs (Swagger UI) and openapi.json (raw). Most SDK users won't need it — the language bindings mirror it closely.

Ways to drive the API

SDKs

Assistive AI

  • POST /api/v1/ai/chat — multi-turn assistive chat used by the web app (command palette and AI panel). Responses are shaped as { data: { reply, suggestions? } }. Requires a configured provider (MISTRAL_API_KEY or OPENAI_API_KEY); otherwise the API returns 503 with AI_NOT_CONFIGURED.
  • GET /api/v1/search/semantic — semantic (embedding) search across indexed cases, knowledge documents, evidence, findings, and audit reports when the database and embeddings provider are available.

Rate limits

  • Default: 1,200 requests/min per API key.
  • Bulk endpoints have separate, lower caps.
  • X-RateLimit-Remaining and X-RateLimit-Reset headers on every response.
  • 429 with Retry-After when you exceed.

Enterprise plans can raise limits; contact us.

Webhook security

Outbound webhooks sign requests with HMAC-SHA256. The signature header is X-Kiket-Signature; the shared secret is shown once when you create the subscription. Always verify before acting — SDK helpers do this for you.

Common tasks

On this page