API Best Practices
Guidelines for integrating with Trillet AI API
Authentication
API Keys
- Keep your API keys secure and never expose them in client-side code
- Use different API keys for development and production
- Rotate your API keys periodically
- Monitor your API key usage for suspicious activity
# API Key format
xxxxxxxxxxxxxxxxxxx
Error Handling
Implement proper error handling for API responses:
curl -X POST https://api.trillet.ai/v1/api/call \
-H "x-api-key: YOUR_API_KEY" \
-H "x-workspace-id: YOUR_WORKSPACE_ID" \
-H "Content-Type: application/json" \
-d '{
"call_agent_id": "agent_123",
"to": "+1234567890"
}'
Common error responses:
{
"error": {
"code": "insufficient_credits",
"message": "Your account has insufficient credits"
}
}
{
"error": {
"code": "invalid_number",
"message": "The provided phone number is invalid"
}
}
Rate Limits
- Production API keys are limited to 60 requests per minute
- Implement backoff when you hit rate limits
- Monitor your API usage in the dashboard
Rate limit response:
{
"error": {
"code": "rate_limit_exceeded",
"message": "Too many requests. Please try again in 60 seconds.",
"reset_at": "2024-01-22T15:30:00Z"
}
}
Production Checklist
-
Authentication
- Use production API keys
- Implement key rotation
- Secure key storage
-
Error Handling
- Handle all error codes
- Implement retry logic
- Log errors appropriately
-
Monitoring
- Track API response times
- Monitor error rates
- Set up alerts