API Overview
Base URL
https://kyt-api.alphatok.xyzAuthentication
Every request uses an API credential in the Authorization header:
Authorization: Bearer <app_id>.<secret>An administrator creates credentials for your organisation. See Authentication.
Quota and upstream limits
Your screening quota and provider throttling are different. GATEWAY_QUOTA_BALANCE_EXHAUSTED means your organisation has spent its cumulative screening quota, which every API key shares and no clock refills; PROVIDER_RATE_LIMITED means the selected provider throttled the upstream call. See Status Codes.
Request id
Every response carries an X-Request-Id header, errors included. Quote it when asking about a call: for a screening it identifies the call record, and for one that consumed quota it is also the id that charge was recorded under. A request rejected before it reaches the API — an unknown path or method — still returns an id, but leaves nothing behind it. The value is generated by the API; sending your own X-Request-Id does not change the one you get back.
Choose provider, capability, then chain
Each screening request uses one provider. Omit provider to use the tenant's current default, or name an enabled provider explicitly; the reply identifies who answered. The schema shows the platform chain union, but the valid subset comes from List capability chains for that provider and capability. Screening requests carry the chain slug in the body; replies carry the chain enum. See AML API. The platform does not merge conclusions across providers.