API & SDKs
Drive Kiket from code — REST, six language SDKs, CLI, MCP, webhooks.
Everything the web app can do is an API call. The API is the single interface; every other surface (SDKs, CLI, MCP) is a thin wrapper over it.
Base URL
https://api.kiket.dev/api/v1Self-hosted deployments use their own domain.
Auth
Two ways to act on behalf of a human in the product, and one for machines:
- Interactive session — Email/password or Google / GitHub OAuth on the web app; short-lived access tokens with refresh (see Sign-in and accounts).
- API key (long-lived, scoped) — what SDKs, CLI, and automation use when there is no browser.
Create an API key in Settings → API Keys. Pass it as a Bearer header:
curl -H "Authorization: Bearer $KIKET_API_KEY" https://api.kiket.dev/api/v1/platform/casesShape
- REST, resource-oriented, JSON bodies.
- Versioned in the URL (
/api/v1). - Cursor paginated on collections (
?cursor=<opaque>&limit=50). - Idempotent on writes via
Idempotency-Keyheader. - RFC 7807 error bodies (
{ "type": "...", "title": "...", "status": 422 }).
Live reference
An OpenAPI spec lives at api.kiket.dev/api/v1/docs (Swagger UI) and openapi.json (raw). Most SDK users won't need it — the language bindings mirror it closely.
Ways to drive the API
SDKs
Six official client libraries: Node.js, Python, Ruby, Java, .NET, Go. Fluent types, auto-retry, idempotency helpers.
CLI
Terminal tooling for one-offs, scripting, and CI pipelines.
MCP server
Model Context Protocol adapter — wire Kiket into Claude, Cursor, any MCP-aware agent.
Webhooks
Subscribe to events and let Kiket call your endpoint.
SDKs
Node.js
TypeScript-first, Promise-based.
Python
Sync + asyncio.
Go
Idiomatic, zero-dep.
Ruby
Rails-friendly.
Java
Java 17+, Maven.
.NET
.NET 8+, NuGet.
Assistive AI
POST /api/v1/ai/chat— multi-turn assistive chat used by the web app (command palette and AI panel). Responses are shaped as{ data: { reply, suggestions? } }. Requires a configured provider (MISTRAL_API_KEYorOPENAI_API_KEY); otherwise the API returns503withAI_NOT_CONFIGURED.GET /api/v1/search/semantic— semantic (embedding) search across indexed cases, knowledge documents, evidence, findings, and audit reports when the database and embeddings provider are available.
Rate limits
- Default: 1,200 requests/min per API key.
- Bulk endpoints have separate, lower caps.
X-RateLimit-RemainingandX-RateLimit-Resetheaders on every response.429withRetry-Afterwhen you exceed.
Enterprise plans can raise limits; contact us.
Webhook security
Outbound webhooks sign requests with HMAC-SHA256. The signature header is X-Kiket-Signature; the shared secret is shown once when you create the subscription. Always verify before acting — SDK helpers do this for you.