跳到正文

鉴权与 API key ​

WebAgent 当前有两种合法调用边界,请不要混用。

原生 HTTP ​

在 Console 创建项目 API key,并将它放在服务端环境变量:

http
Authorization: Bearer wa_xxxxxxxxxxxxxxxxxxxxxxxx

请求路径是 https://webagent.qoni.ai/api/v1/projects/{pid}/...。{pid} 必须和 key 的 project scope 一致;不使用 X-Project-Id header。

Node SDK ​

Node SDK @qoniai/qoni 不接受 apiKey / projectId 这种旧版 Client 配置。它只在可信服务端保存 Qoni AK/SK:

ts
const qoni = new Qoni({
  accessKey: process.env.QONI_ACCESS_KEY!,
  secretKey: process.env.QONI_SECRET_KEY!,
});

运行时产品调用前,使用真实 GenAuth 用户 ID 获取委托 token:

ts
const { token } = (await qoni.delegateToken({
  user: { id: process.env.QONI_USER_ID! },
  products: ["doAnything"],
})).data;

然后把 token 传给 qoni.doAnything.run()、qoni.deepResearch.run()、qoni.webSearch.run() 或 qoni.track.create()。不要自行调用 SDK 的 runtime discovery 或 token-exchange 内部路径。

密钥轮换 ​

  • 不要把任何 key、AK/SK 或 delegation token 提交到 git。
  • 生产环境使用 secret manager。
  • 轮换 API key 后,先部署新 key,再撤销旧 key。