Pages without a backend
Mint signed URLs where the key lives; the browser loads them without one.
/api/v1/image-urlsMint where the key lives, load anywhere
A static site, a CMS page, an email or a spreadsheet has no server to keep a key in, and a key in a page is a key everyone has. So the key stays in the one place you do run code, a build step, an edge function or a cron, and that place mints signed URLs: one request takes up to 50 images, each URL is one credit when it is created, and anyone holding it loads the image without a key until expires_at. Put the URL in the <img> and ship the page.
curl --fail-with-body \
-X POST https://carimage.dev/api/v1/image-urls \
-H "Authorization: Bearer $CAR_IMAGE_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: listing-8812-hero" \
-d '{"images":[{"vehicle":"veh_395yw8tn73ff8","view":"front-3-4","width":800,"height":500,"trim":true,"format":"auto"}],"ttl_seconds":604800,"renew":true}'
# → data[0].url: "https://carimage.dev/api/v1/delivery/eyJhbGciOi…" (expires_at a week out, renews_until a year out)
# anywhere, with no key:
# <img src="https://carimage.dev/api/v1/delivery/eyJhbGciOi…" alt="2023 Ford F-150, front three-quarter" width="800" height="500" loading="lazy">Renewal, and the format the viewer gets
Loading a URL is free until expires_at, which ttl_seconds sets up to a week ahead. A page you rebuild every week can simply mint again; an email, a PDF or a page nobody republishes cannot, so mint those with renew: true: the first load in each further window of ttl_seconds bills one more credit and keeps the URL alive, for as long as renew_days allows, and a window nobody opens costs nothing (auto-renewing URLs). format: "auto" lets every load negotiate WebP or PNG for the browser that asks.
Idempotency-Key: a retry with the same key replays the answer and never bills twice (safe retries).The long version, with the email HTML and the credit math: the email story.