Skip to content

Authentication ​

The Hyperion API uses Bearer token authentication to identify users with premium plans.

Usage ​

To authenticate your requests, include your API key in the Authorization header:

bash
curl -H "Authorization: Bearer YOUR_API_KEY" https://api.sylvain.sh/v6/infos

Checking Your Plan ​

Use GET /auth to check which tier a token resolves to, along with its limits:

bash
curl -H "Authorization: Bearer YOUR_API_KEY" https://api.sylvain.sh/auth
json
{
    "authenticated": true,
    "tier": "pro",
    "limits": {
        "hourly": 6000,
        "burst": 120
    }
}

Without a token, it returns the default tier instead of an error:

json
{
    "authenticated": false,
    "tier": "default",
    "limits": {
        "hourly": 2000,
        "burst": 50
    }
}

An invalid token returns the same 401 shown below.

Rate Limits ​

PlanRequests/hourBurst/10s
Free2,00050
Advanced3,50080
Pro6,000120
Business10,000200

Burst Limit

The burst limit prevents sending too many requests in a short window. If you exceed the burst limit, you will receive a 429 Too Many Requests response.

See the Pricing page for more details.

Rate Limit Headers ​

Every response carries your current quota, so a client can pace itself instead of discovering its limit by hitting it.

HeaderDescription
X-RateLimit-LimitRequests allowed in the current window
X-RateLimit-RemainingRequests left in the current window
X-RateLimit-ResetWhen the window resets
Retry-AfterSeconds to wait before retrying, sent only on a 429

New in 6.0.0

These headers did not exist before 6.0.0. Read X-RateLimit-Remaining on every response and slow down as it approaches zero, rather than waiting for a 429.

Error Responses ​

Invalid Token ​

If the provided token is incorrect or expired:

json
{
    "message": "Unauthorized",
    "error": "Invalid token.",
    "status": 401
}

No Token ​

Note

If no token is provided, the request is treated as unauthenticated and uses the Free tier limits (2,000 requests/hour).

Getting an API Key ​

To obtain an API key, purchase a plan on the Pricing page. Your unique token will be sent to your email after purchase.