Voxelion API
Perceptual data integrity: deduplication for medical imaging datasets. Detects near-identical images and whole redundant scans leaking across train/validation splits.. One HTTP API, three engines, and a single unit of billing: the size of what you send.
The API is available at https://api.voxelion.ai. Everything below works
identically against the sandbox at https://sandboxapi.voxelion.ai, which runs the same
build against a separate database — see Sandbox.
Authentication
Every endpoint below takes `Authorization: Bearer <token>`. Two kinds of token are accepted.
| Method | Looks like | Use it for |
|---|---|---|
API key | Authorization: Bearer pk_live_… | Server-to-server integrations. Create one in the console under API Keys. |
Session | Authorization: Bearer <jwt> | The console itself, after a magic-link sign-in. Not intended for integrations. |
Administrative endpoints accept sessions only — an API key can never perform them.
A key is shown once. The secret is returned by the create call and never again — only a masked snippet is stored. If it is lost, revoke it and issue another; there is no recovery path, by design.
Quickstart
Three calls from nothing to a deduplicated dataset.
- 1. Grant consent once: POST /api/consent { "version": "2026-07-04" }
- 2. Add credit in the console (Credits & Billing), or the next call returns 402.
- 3. Deduplicate: POST /api/dedup with multipart files[]
curl -X POST https://api.voxelion.ai/api/dedup \
-H 'Authorization: Bearer pk_live_xxxxx' \
-F 'files=@scan-001.dcm' -F 'files=@scan-002.dcm'
The response is a report: one entry per file with its hash, the near-duplicate pairs found, the clusters those pairs form, and the leakage fraction. Nothing is deleted — Voxelion tells you what is redundant and hands you a keep/drop manifest. Acting on it is yours.
Sandbox
The sandbox is a complete second deployment: its own database, its own accounts, its own credit balances. It is the right place to develop an integration, because nothing you do there can touch production data.
| Production | Sandbox | |
|---|---|---|
| Console | app.voxelion.ai | sandbox.voxelion.ai |
| API | api.voxelion.ai | sandboxapi.voxelion.ai |
| Accounts | Self-service sign-in | An administrator approves each account before first sign-in |
| Data | Live | Disposable — treat it as such |
Sandbox accounts are held for approval, so request access before you need it rather than at the moment you start integrating. Request sandbox access.
Consent
Server-side image processing requires a one-time data-processing consent grant, per account.
Server-side processing requires an explicit, versioned consent record. Check it with
GET /api/consent and grant it with POST /api/consent. Calls made
before consent is recorded are refused with 403 CONSENT_REQUIRED — the check runs
before the upload is read, so a refused request never puts your files on our disk.
Currently enforced on: POST /api/dedup, POST /api/jobs.
In-browser runs never need consent, because nothing is uploaded. The console's local mode and the no-account demo both hash images in the browser; the pixels do not leave the machine, so there is nothing to consent to.
Rate limits
Applied per authenticated identity (per API key, or per session), not per IP.
| Credential | Requests per window | Window |
|---|---|---|
| API key | 60 | 60s |
| Session | 300 | 60s |
Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and
X-RateLimit-Reset. On 429 a Retry-After header tells you
how long to wait — read it rather than guessing, and see
retry semantics.
Limits are keyed to the credential, not the IP address, so several keys from one office do not share a budget.
Reference generated from live API (https://api.voxelion.ai) on 2026-08-30. The endpoint list, error codes and limits on this page are produced from the API's own route table — if an endpoint is not listed here, it is not enabled on production.