Authentication and API keys
There are two supported integration boundaries; do not mix them.
Raw HTTP
Create a project API key in Console and keep it on the server:
http
Authorization: Bearer wa_xxxxxxxxxxxxxxxxxxxxxxxxUse https://webagent.qoni.ai/api/v1/projects/{pid}/...; {pid} must match the key's project scope.
Node SDK
The current @qoniai/qoni SDK does not use the old new Client({ apiKey, projectId }) configuration. Keep Qoni AK/SK on the server:
ts
const qoni = new Qoni({
accessKey: process.env.QONI_ACCESS_KEY!,
secretKey: process.env.QONI_SECRET_KEY!,
});Before a runtime product call, request a user delegation token:
ts
const { token } = (await qoni.delegateToken({
user: { id: process.env.QONI_USER_ID! },
products: ["doAnything"],
})).data;Pass that token to qoni.doAnything.run(), qoni.deepResearch.run(), qoni.webSearch.run(), or qoni.track.create(). Do not hand-roll runtime discovery or token exchange.
Key hygiene
Never commit keys or delegation tokens. Use a secret manager in production and rotate by deploying the new key before revoking the old one.