REST API

A smaller, deliberately chosen surface.

Not everything the app can do — create a job, read its state, fetch assets, schedule a post, read usage. Every published endpoint is a promise (docs/23 §1).

Authentication

API keys, scoped to one workspace — never a session cookie, never a password. A key is shown once at creation and stored hashed; a leaked key is identifiable by its tonta_sk_live_/tonta_sk_test_ prefix and last-four suffix in the dashboard. Two active keys are allowed per workspace so you can rotate without downtime.

jobs:readjobs:writeassets:readassets:writeschedule:readschedule:writepublish:writeconnections:writeusage:readgoals:readgoals:write

Idempotency

An Idempotency-Key header is required on every POST that spends money. The first response is replayed for 24 hours — retry safely, never double-charged.

Webhooks

Polling a job for twenty minutes is a bad integration, so Tonta pushes. Events include job.completed, job.failed, job.needs_review, job.awaiting_input, piece.ready, post.published, post.failed, connection.reauth_required, credit.low, credit.exhausted and subscription.updated.

  • · Signed: Tonta-Signature: t=<unix>,v1=<hmac-sha256 of "t.body"> with a 5-minute tolerance.
  • · At least once — deliveries can repeat or arrive out of order; the event id is the dedupe key.
  • · Retried on any non-2xx: 8 attempts with backoff over roughly 24 hours, then the endpoint is marked failing.
  • · Every attempt is visible in the dashboard for 30 days, with a manual replay button.

Rate limits

Per plan: Pro gets 60 requests/minute and 10 jobs/hour; Studio gets 300 requests/minute and 60 jobs/hour. Lower tiers have no API access. A 429 carries Retry-After and X-RateLimit-* headers.

The published surface (v1)

POST/api/v1/jobsCreate a jobjobs:write
GET/api/v1/jobs/:idState, cost, progressjobs:read
GET/api/v1/jobsList, filterablejobs:read
POST/api/v1/jobs/:id/cancelCanceljobs:write
POST/api/v1/jobs/estimatePrice without committing—
GET/api/v1/capabilitiesPresets this plan may use—
GET/api/v1/content/:idA finished piece and its variantsassets:read
GET/api/v1/assets/:id/urlShort-lived signed URLassets:read
POST/api/v1/scheduleSchedule a pieceschedule:write
GET/api/v1/scheduleUpcoming and past postsschedule:read
DELETE/api/v1/schedule/:idCancelschedule:write
GET/api/v1/usageCredits by day, job and serviceusage:read
GET/api/v1/balanceBalance, held, next expiryusage:read
POST/api/v1/webhooksRegister an endpoint—
GET/api/v1/webhooksList—
DELETE/api/v1/webhooks/:idRemove—
POST/api/v1/webhooks/:id/testSend a test delivery—

An OpenAPI document generated from the same schemas the handlers use is planned but not yet served publicly — check the changelog for when it lands.

Get an API key

Available on Pro and Studio. Create and rotate keys from Settings → API keys once you're signed in.

Manage API keys