鉴权与 API key
WebAgent 当前有两种合法调用边界,请不要混用。
原生 HTTP
在 Console 创建项目 API key,并将它放在服务端环境变量:
http
Authorization: Bearer wa_xxxxxxxxxxxxxxxxxxxxxxxx请求路径是 https://webagent.qoni.ai/api/v1/projects/{pid}/...。{pid} 必须和 key 的 project scope 一致;不使用 X-Project-Id header。
Node SDK
Node SDK @qoniai/qoni 不接受 apiKey / projectId 这种旧版 Client 配置。它只在可信服务端保存 Qoni AK/SK:
ts
const qoni = new Qoni({
accessKey: process.env.QONI_ACCESS_KEY!,
secretKey: process.env.QONI_SECRET_KEY!,
});运行时产品调用前,使用真实 GenAuth 用户 ID 获取委托 token:
ts
const { token } = (await qoni.delegateToken({
user: { id: process.env.QONI_USER_ID! },
products: ["doAnything"],
})).data;然后把 token 传给 qoni.doAnything.run()、qoni.deepResearch.run()、qoni.webSearch.run() 或 qoni.track.create()。不要自行调用 SDK 的 runtime discovery 或 token-exchange 内部路径。
密钥轮换
- 不要把任何 key、AK/SK 或 delegation token 提交到 git。
- 生产环境使用 secret manager。
- 轮换 API key 后,先部署新 key,再撤销旧 key。