Skip to main content

Core API — Usage Reports & Credit Balance

The Core API returns your account's API usage and credit balance as JSON, the same figures as your dashboard, so you can build your own reports, dashboards and alerts. It takes the API key you already use; every endpoint is GET, calls are free and do not appear in your usage, and responses carry no personal data.

  • Base URL: https://iapp.co.th/api/core/v1
  • Header: apikey: YOUR_API_KEY (x-api-key also works). Your key is in API Key Management.
curl "https://iapp.co.th/api/core/v1/credits" \
-H "apikey: YOUR_API_KEY"
{
"success": true,
"data": {
"balance": 1234.56,
"currency": "IC",
"validUntil": "2027-01-31T16:59:59.000Z"
}
}

Call it from a server, a scheduled job or a BI tool, never from browser JavaScript: the key would be readable in the page source, and browser calls are blocked by CORS.

Endpoints​

EndpointReturns
/pingConfirms the key works
/creditsRemaining credit balance in IC
/usage/summaryHeadline figures for a period: requests, credits, average latency, success rate, top endpoints
/usage/timeseriesRequests and credits per hour, day, week or month
/usage/servicesOne row per service: requests, credits, latency, error rate
/usage/keysOne row per API key, with its name
/usage/recordsOne row per call, with filters, sorting and pagination

Every /usage/* endpoint takes startDate and endDate (YYYY-MM-DD or ISO 8601; default the last 30 days). All but /usage/keys also take apiKeyId to report on one key.

Parameters and responses​

No parameters beyond the shared ones.

curl "https://iapp.co.th/api/core/v1/usage/summary?startDate=2026-08-01&endDate=2026-08-05" \
-H "apikey: YOUR_API_KEY"
{
"success": true,
"data": {
"period": { "startDate": "2026-08-01T00:00:00.000Z", "endDate": "2026-08-05T00:00:00.000Z" },
"totalRequests": 18342,
"totalCredits": 2311.75,
"avgLatencyMs": 412,
"successRate": 99.12,
"topEndpoints": [
{ "endpoint": "/thai-ocr/v3.5/ocr-document", "requests": 9120, "credits": 1824.0 },
{ "endpoint": "/v3/store/data/thai-legal/search", "requests": 4210, "credits": 421.0 }
]
}
}

Per-key reporting​

Create one API key per application or customer in API Key Management. /usage/keys returns one row per key with its keyId, the key's id and never the key itself; pass it as apiKeyId to any other /usage/* endpoint to scope that report to the key. A deleted key still appears, with keyId, keyName and keyPrefix set to null, so account totals reconcile.

Examples​

import requests

BASE = "https://iapp.co.th/api/core/v1"
HEADERS = {"apikey": "YOUR_API_KEY"}

credits = requests.get(f"{BASE}/credits", headers=HEADERS).json()["data"]
series = requests.get(
f"{BASE}/usage/timeseries",
headers=HEADERS,
params={"startDate": "2026-08-01", "groupBy": "day"},
).json()["data"]

print(f"Balance: {credits['balance']:.2f} IC")
for point in series["points"]:
print(f"{point['date'][:10]} {point['requests']:>6} calls {point['credits']:>8.2f} IC")

For Postman, import the collection and the production environment, then set the apikey variable.

Limits​

  • 120 requests a minute per API key; beyond that, HTTP 429. For a dashboard, a poll every 30 to 60 seconds is enough.
  • A call appears in the usage records within seconds; the credit balance is real time.
  • History is kept as long as the web dashboard keeps it. To archive it, pull /usage/records on a schedule and store the rows.

Data handling​

The API is read-only: it cannot create keys, spend credits, change settings or delete anything. Responses carry no name, email, user ID, client IP, request headers or request and response contents; endpoint paths lose their query strings, and API keys appear only as prefixes, never in full. A key reaches only its own account, and an apiKeyId that is not one of its keys returns 404; if a key leaks, revoke it in API Key Management and its usage history stays.

Errors​

HTTPCodeMeaning
400VALIDATION_ERRORA bad parameter; error.details.errors lists each problem
401UNAUTHORIZEDMissing or invalid API key
403FORBIDDENAccount not active
404NOT_FOUNDapiKeyId is not one of this account's keys
429TOO_MANY_REQUESTSOver 120 requests a minute for this key
503SERVICE_UNAVAILABLETemporary backend issue; retry with backoff

Every error has one shape:

{
"success": false,
"error": { "code": "UNAUTHORIZED", "message": "Invalid API key." }
}

© 2026 iApp Technology Co., Ltd.TermsPrivacyStatussale@iapp.co.th