Enterprise API
Authentication
The enterprise API authenticates every request with an API key tied to your Obsidian account and plan.
API keys
Keys are prefixed with obsidian_sk_. A key searches regulations, enforcement actions and standards within your plan perimeter : the industries and jurisdictions of your account (of your company for a team member), limited to the industries listed on the key when it was created. A key cannot act for another account. Treat a key like a password : anyone holding it can spend your verified requests.
Sending the key
Provide the key on every request, using either header form:
# Preferred: X-API-Key header curl https://api.obsidianri.com/frameworks \ -H "X-API-Key: obsidian_sk_your_key_here" # Also supported: Authorization Bearer curl https://api.obsidianri.com/frameworks \ -H "Authorization: Bearer obsidian_sk_your_key_here"
A missing or malformed key returns 401 Unauthorized with the detail "Missing API key. Provide via X-API-Key header or Authorization: Bearer <key>". Keep keys server‑side : never ship them in a browser or mobile app.
Managing keys
Keys are created and revoked from your Obsidian account, under Account, API, which lists each key by its prefix with its status, usage and the industries it covers.
- Shown once. The full key appears only at creation. Obsidian keeps a fingerprint of it, never the key itself, so it cannot be shown again : copy it then.
- Rotate. Create a new key, switch your integration to it, then revoke the old one. A revoked key stops working at once.
- After a plan change. A key keeps the industries it was created with : create a new key to cover an industry added to your plan.
Rate & usage limits
Usage is metered in verified requests per month and enforced per account, not per key : all of an account's keys draw from the same allowance.
| Plan | Verified requests / month |
|---|---|
| Free | 50 |
| Pro | 500 |
| Expert | 5,000 |
Once the monthly allowance is spent, data endpoints return 402 Payment Required until the next cycle or a plan upgrade.