API changelog
The AIR HTTP API is pre-1.0 and unversioned — paths do not include a version prefix. Breaking changes are announced here before deploy.
2026-08-14 — Credits, feedback, and actionable 402
What changed
- New endpoints, all usable with any key you already hold — they require no new scope:
GET /billing/credits— plan, status, balance, andassessmentCreditCost.POST /billing/credit-purchase-link— a URL a person opens to buy credits. Creates a link only; no charge occurs until a human completes checkout.POST /support/credit-request— ask Thalus for credits. Staff reply by email, to the organization owner unless you name another address.POST /support/feedback— send product feedback.POST /support/feedback/public— unauthenticated feedback, for someone whose signup or key creation failed.
InsufficientCreditsErrorandTrialExpiredError(both402) now carry a requiredrecoverystring naming the next step.- The two
/billingendpoints are not in the generated API reference — they sit in the portal-annotated billing group. Credits and feedback is their contract.
Nothing breaks. These are additions, and the recovery field is new on errors you were already handling.
What integrators should do
- Call
GET /billing/creditsand comparecredits.availableagainstassessmentCreditCostbefore starting an assessment, rather than discovering a402mid-run. - On
402, display therecoverystring verbatim instead of your own wording, so your client and the AIR portal say the same thing. - Leave
contactEmailout unless a person asked to be replied to elsewhere. An API key has no mailbox, so the reply goes to the organization owner. Never let a model fill this field — it will offer an address it read earlier in the conversation, and the reply then reaches someone unrelated to the organization. - If your client drafts feedback with a model, have a person review and submit it.
See Credits and feedback.
2026-07-07 — Domain-scoped API keys
What changed
- API keys are scoped to a domain, not an entire organization.
- Service account and key management is per domain in the portal.
- Each key can access only resources in the domain where it was created.
What integrators should do
- Sign in at https://air.thalus.ai and create a new key in each domain you automate against.
- Call
GET /domains/to confirm which domain your key belongs to. - Use
GET /domains/<domainPid>/projectsto list projects — do not assume org-wide access.
See Authentication and Getting started.
2026-07-06 — API key scope enforcement
What changed
- Integrator routes check per-key scopes (
projects:read,assessments:write, etc.). - Key creation requires a non-empty
scopesarray. - Write scopes imply read on the same resource.
integrations:fullgrants all integrator scopes.
What integrators should do
- Review existing keys in the portal.
- If you receive
403withAPI key missing required scope: …, create a new key with the scopes from Recommended presets.
2026-07-06 — Service-account integrator access
What changed
- Bearer API keys can call projects, assessments, domains, search, and portfolio endpoints.
- Async work is tracked by polling document and assessment status.
What integrators should do
- Use Async jobs for upload → assess → report automation.
2026-07-06 — Initial public documentation
What changed
- Public documentation at https://air.thalus.ai/docs.
- OpenAPI at
https://api.air.thalus.ai/openapi.json.
Related
- Errors — status codes and rate limits
- API reference