Skip to main content

API changelog

The AIR HTTP API is pre-1.0 and unversioned — paths do not include a version prefix. Breaking changes are announced here before deploy.

2026-08-14 — Credits, feedback, and actionable 402​

What changed

  • New endpoints, all usable with any key you already hold — they require no new scope:
    • GET /billing/credits — plan, status, balance, and assessmentCreditCost.
    • POST /billing/credit-purchase-link — a URL a person opens to buy credits. Creates a link only; no charge occurs until a human completes checkout.
    • POST /support/credit-request — ask Thalus for credits. Staff reply by email, to the organization owner unless you name another address.
    • POST /support/feedback — send product feedback.
    • POST /support/feedback/public — unauthenticated feedback, for someone whose signup or key creation failed.
  • InsufficientCreditsError and TrialExpiredError (both 402) now carry a required recovery string naming the next step.
  • The two /billing endpoints are not in the generated API reference — they sit in the portal-annotated billing group. Credits and feedback is their contract.

Nothing breaks. These are additions, and the recovery field is new on errors you were already handling.

What integrators should do

  1. Call GET /billing/credits and compare credits.available against assessmentCreditCost before starting an assessment, rather than discovering a 402 mid-run.
  2. On 402, display the recovery string verbatim instead of your own wording, so your client and the AIR portal say the same thing.
  3. Leave contactEmail out unless a person asked to be replied to elsewhere. An API key has no mailbox, so the reply goes to the organization owner. Never let a model fill this field — it will offer an address it read earlier in the conversation, and the reply then reaches someone unrelated to the organization.
  4. If your client drafts feedback with a model, have a person review and submit it.

See Credits and feedback.

2026-07-07 — Domain-scoped API keys​

What changed

  • API keys are scoped to a domain, not an entire organization.
  • Service account and key management is per domain in the portal.
  • Each key can access only resources in the domain where it was created.

What integrators should do

  1. Sign in at https://air.thalus.ai and create a new key in each domain you automate against.
  2. Call GET /domains/ to confirm which domain your key belongs to.
  3. Use GET /domains/<domainPid>/projects to list projects — do not assume org-wide access.

See Authentication and Getting started.

2026-07-06 — API key scope enforcement​

What changed

  • Integrator routes check per-key scopes (projects:read, assessments:write, etc.).
  • Key creation requires a non-empty scopes array.
  • Write scopes imply read on the same resource.
  • integrations:full grants all integrator scopes.

What integrators should do

  1. Review existing keys in the portal.
  2. If you receive 403 with API key missing required scope: …, create a new key with the scopes from Recommended presets.

2026-07-06 — Service-account integrator access​

What changed

  • Bearer API keys can call projects, assessments, domains, search, and portfolio endpoints.
  • Async work is tracked by polling document and assessment status.

What integrators should do

  • Use Async jobs for upload → assess → report automation.

2026-07-06 — Initial public documentation​

What changed