Generation endpoints use bring-your-own-key authentication. Send the Gemini key in X-API-Key; it is not persisted.
curl -X POST -H "X-API-Key: YOUR_KEY" -H "Content-Type: application/json" \
-d '{"prompt":"A product on marble","tier":"balanced"}' \
https://photogen.ashbi.ca/api/generate| Method | Path | Purpose |
|---|---|---|
| GET | /api/whoami | Report BYOK/server-key mode. |
| POST | /api/validate-key | Validate a Gemini key without storing it. |
| POST | /api/generate | Start image generation and return a job ID. |
| GET | /api/jobs/<job_id> | Read an authenticated job result. |
| POST | /api/composite | Place an uploaded product in a generated scene. |
| POST | /api/export | Export an output using platform presets. |
| POST | /api/qc | Evaluate an output against the visual QC rubric. |
| POST | /api/campaigns/<id>/bundles | Create private exact channel deliverables. |
| GET | /api/campaigns/<id>/bundles/<bundle_id>/download | Download an owner-scoped campaign ZIP. |
| GET | /image/<path> | Serve an immutable generated image. |