These pages describe the Training API update on
codex/knowlify-training-api-updates.
The update has not yet been deployed or verified end to end on a live environment.
New fields, stricter edit behavior, and website brand lookup require the updated API and worker.
See Testing and availability.Workspace scope
- Personal keys can access the owner’s personal videos, not organization-linked videos.
- Organization keys can access videos linked to that organization, subject to current membership.
- Broader access available to the key creator in the app does not widen the key’s scope.
- Edit polling and revert verify access to both the edit record and its underlying video.
- Listing and job actions follow the same workspace checks. Deleted chats remove job access, so detail and action routes return 404.
org_id when using an API key. If supplied, it must match the key’s scope; a mismatch returns 400. A personal key cannot select an organization through the request body.
Supported routes
Keys authorize the Training routes listed in the API reference and the Marketing video routes supported by the deployment. Other app routes may require a first-party session. First-party clients can useAuthorization: Bearer <jwt> with their authenticated session. Session access rules are separate from API-key scope; do not use app-session access as a test of a key’s permissions.
