API Keys & Security
Environments, key security, hashing, and rate limits.
API Keys & Security
Wevi API keys provide secure programmatic access to Wevi’s REST endpoints and Model Context Protocol (MCP) server.
Environments
Wevi provides two distinct execution environments:
1. Live (wevi_live_...)
- Produces production-grade video renders. Quality follows your plan: free plans export 720p with a watermark, Pro and Enterprise export up to 4K without one.
- Spends API & MCP credits (see below). Your plan's allowance is used first, then any purchased credits.
- Used for customer-facing video generation, Zapier bots, and production apps.
2. Test (wevi_test_...)
- Every scene render carries the Wevi watermark, regardless of plan.
- Exports are capped at 720p (a higher
qualityis accepted but downgraded). - Renders and exports do not count against your monthly quota, but each key has a hard daily sandbox allowance (below).
- Projects created with a test key stay sandboxed even when opened later in the web app; sandbox exports are labelled "(Sandbox)" and carry
sandbox: true. - Ideal for local integration testing, CI/CD automated test pipelines, and MCP experimentation.
Sandbox daily allowance
| Limit | Per test key | Resets |
|---|---|---|
| Scene renders | 20 / day | 00:00 UTC |
| Video exports | 5 / day | 00:00 UTC |
| Scenes per project | 4 | — |
Unchanged scenes are reused between publishes and do not count again. When a cap is hit the API returns 429 with limit, used, requested and resetsAt, and the MCP tool relays that message. Switch to a wevi_live_ key for production volume.
API & MCP credits
Every action a live key performs is metered in credits. Web sessions and sandbox keys never spend credits.
What costs what
| Action | Credits |
|---|---|
| Scene render (new or changed scene) | 1 |
| Export at 720p | 1 |
| Export at 1080p | 2 |
| Export at 4K | 4 |
Storyboard draft (POST /ai/storyboard/draft) | 1 |
Web UI capture (POST /browse/capture) | 1 |
A 3-scene 1080p video costs 5 credits. Re-publishing a project re-renders only changed scenes, so retries are cheap.
Included in each plan
| Plan | Included credits | Reset |
|---|---|---|
| Free | 10 | Lifetime (one-time allowance to try MCP) |
| Pro (monthly or yearly) | 150 / month | With your billing period |
| Enterprise | Unlimited | — |
Top-up packs
Buy more from Profile → API Keys & MCP → Buy credits (or the pricing page). Packs are one-time purchases, never reset, and are used after your plan allowance. Free users can buy a pack to use MCP without subscribing.
The packs on sale and their prices can change; the current list always comes back from GET /billing/credits (packs) and the wevi_get_credits tool. At the time of writing:
| Pack | Credits | Price |
|---|---|---|
| Starter | 50 | $15 |
| Builder | 200 | $49 |
| Scale | 1,000 | $199 |
When credits run out
The API returns 402 Payment Required:
{
"statusCode": 402,
"error": "Insufficient credits",
"message": "This action needs 3 credits but 1 is available. Buy a credit pack or upgrade your plan at https://app.wevi.ai/app/profile?id=api-keys&topup=1.",
"creditsRequired": 3,
"creditsAvailable": 1,
"planRemaining": 1,
"purchasedBalance": 0,
"topUpUrl": "https://app.wevi.ai/app/profile?id=api-keys&topup=1"
}The MCP wevi_get_credits tool and GET /billing/credits return your balance, per-action costs and the packs on sale, so an agent can check before starting a large batch.
Where usage shows up
- Your dashboard (Profile → API Keys & MCP): plan credits used, purchased balance, spend per key, sandbox allowance for today, and recent API activity.
Key limits & lifecycle
| Rule | Value |
|---|---|
| Active Live keys per account | 10 |
| Active Test keys per account | 5 |
| Revocation | Immediate; the next request gets 401 |
| Expiry | Optional date set at creation; expired keys are refused like revoked ones |
| Retention | Revoked and expired keys are kept on record with their usage history. The dashboard hides them after 30 days behind a "Show older revoked" toggle |
Security Architecture
- One-Time Secret Display: When an API key is generated, the plaintext secret is revealed only once. Wevi does not store the raw secret key.
- SHA-256 Hash Storage: The backend hashes keys with SHA-256 before storing them in PostgreSQL.
- Instant Revocation: Revoking a key from your dashboard immediately disconnects all active Claude Desktop instances and API clients.
Rate Limits
| Environment | Rate Limit |
|---|---|
| Standard API | 120 requests per minute per IP/key |
| Render Export Trigger | Concurrency controlled by plan tier (Free: 1 concurrent, Pro/Enterprise: high concurrency) |
If you exceed 120 requests/minute, the server responds with HTTP status 429 Too Many Requests.