> ## Documentation Index
> Fetch the complete documentation index at: https://docs.domino.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Ask whether your Bearer token may invoke this Model API

> Confirm that the caller in `Authorization: Bearer` may invoke this Model API.
Use this from the Classic Model API sidecar (or any headless client) before
forwarding an inference request. A successful check is HTTP 200 with an empty
body. There is no JSON `canInvoke` field and no login or OAuth redirect.

This is a beta route behind an install-wide identity-invocation flag. When
that flag is off, this endpoint rejects the request. Legacy Model Access
Tokens stay on the sidecar local allowlist and do not use this route.

Public visibility allows every authenticated Domino user to invoke.
Discoverable and Private require an assigned Owner, Editor, or Viewer.
Discoverable alone does not grant invoke. Public still requires a valid
Domino identity; callers are never anonymous.

Related:
- GET /api/modelServing/v1/modelApis/{modelApiId} (read Model API metadata)
- GET /api/modelServing/beta/modelApis/{modelApiId}/visibility (read visibility)
- GET /api/modelServing/beta/modelApis/{modelApiId}/collaborators (list assigned roles)




## OpenAPI

````yaml /api-specs/cloud/public-api.json get /api/modelServing/beta/modelApis/{modelApiId}/consumer/access
openapi: 3.0.3
info:
  title: Domino Public API
  description: Reference for Domino's public REST API endpoints.
  version: 6.4.0
  x-catalog-key: nucleus
servers:
  - url: https://mycluster.domino.tech
    description: >-
      Replace 'mycluster.domino.tech' with your Domino cluster hostname. For
      Domino Cloud customers, that is `your-subdomain`.domino.tech (e.g.,
      acme.domino.tech). For self-hosted deployments, it is the hostname you
      reach the Domino UI at.
security: []
tags:
  - name: Projects
  - name: Project templates
  - name: Workspaces
  - name: Jobs
  - name: HPC Jobs
  - name: Environments
  - name: Hardware Tiers
  - name: Datasets
  - name: Data Sources
  - name: GenAI
  - name: AI Systems
  - name: Apps
  - name: App versions
  - name: App instances
  - name: Model APIs
  - name: Registered models
  - name: Model deployment
  - name: Extensions
  - name: Cost and billing
  - name: Users and organizations
  - name: Service accounts
  - name: Personal Access Tokens
  - name: Personal Access Tokens (admin)
  - name: Audit Trail
  - name: Custom metrics
  - name: PPM
  - name: Model Monitoring models
  - name: Model Monitoring drift and quality
  - name: Model Monitoring settings
  - name: Model Monitoring authentication
  - name: Governance bundles
  - name: Governance policies
  - name: Governance evidence and results
  - name: Governance operations
  - name: NetApp Volumes
  - name: NetApp Volumes snapshots
  - name: NetApp Volumes filesystems
  - name: NetApp Volumes transfers
  - name: Tags
  - name: Properties
externalDocs:
  description: OpenAPI
  url: https://swagger.io/resources/open-api/
paths:
  /api/modelServing/beta/modelApis/{modelApiId}/consumer/access:
    get:
      tags:
        - Model APIs
      summary: Ask whether your Bearer token may invoke this Model API
      description: >
        Confirm that the caller in `Authorization: Bearer` may invoke this Model
        API.

        Use this from the Classic Model API sidecar (or any headless client)
        before

        forwarding an inference request. A successful check is HTTP 200 with an
        empty

        body. There is no JSON `canInvoke` field and no login or OAuth redirect.


        This is a beta route behind an install-wide identity-invocation flag.
        When

        that flag is off, this endpoint rejects the request. Legacy Model Access

        Tokens stay on the sidecar local allowlist and do not use this route.


        Public visibility allows every authenticated Domino user to invoke.

        Discoverable and Private require an assigned Owner, Editor, or Viewer.

        Discoverable alone does not grant invoke. Public still requires a valid

        Domino identity; callers are never anonymous.


        Related:

        - GET /api/modelServing/v1/modelApis/{modelApiId} (read Model API
        metadata)

        - GET /api/modelServing/beta/modelApis/{modelApiId}/visibility (read
        visibility)

        - GET /api/modelServing/beta/modelApis/{modelApiId}/collaborators (list
        assigned roles)
      operationId: canInvokeModelApi
      parameters:
        - description: >
            Model API id (24-character hex). Copy `id` from GET
            /api/modelServing/v1/modelApis

            or from the Model API details URL. The sidecar uses the same id in

            `/api/modelServing/beta/modelApis/{modelApiId}/consumer/access`.
          in: path
          name: modelApiId
          required: true
          schema:
            type: string
      responses:
        '200':
          description: >
            You may invoke this Model API. The body is empty; treat the status
            code as

            the answer. Cache-Control max-age is the sidecar cache TTL (default
            300

            seconds).
          headers:
            Cache-Control:
              description: Maximum time the sidecar may reuse this allow result.
              example: max-age=300
              schema:
                type: string
        '400':
          description: |
            modelApiId is not a 24-character hex ObjectId. Copy the id from
            GET /api/modelServing/v1/modelApis and retry.
        '401':
          description: >
            Domino did not accept the Bearer token before authorization ran.
            Send

            `Authorization: Bearer` with a Domino PAT, service account token, or

            OAuth JWT. This route does not redirect to login.
        '403':
          description: >
            You cannot invoke this Model API. The body is empty; treat the
            status

            code as the answer. Typical causes:

            - No authenticated principal (anonymous requests do not invoke,
            including Public).

            - Identity-based invocation is disabled for the installation. Use a
            legacy
              Model Access Token on the sidecar local path, or ask an administrator to
              enable identity invocation.
            - Visibility is Discoverable or Private and you are not an assigned
            Owner,
              Editor, or Viewer. Ask an Owner to grant at least Viewer, or set
              visibility to Public.
          headers:
            Cache-Control:
              description: Maximum time the sidecar may reuse this deny result.
              example: max-age=300
              schema:
                type: string
        '404':
          description: >
            No Model API exists for modelApiId. The body is empty. Confirm the
            id from

            GET /api/modelServing/v1/modelApis. Cache-Control is set so the
            sidecar

            may cache the miss.
          headers:
            Cache-Control:
              description: Maximum time the sidecar may reuse this not-found result.
              example: max-age=300
              schema:
                type: string
      security:
        - DominoApiKey: []
        - BearerAuthentication: []
components:
  securitySchemes:
    DominoApiKey:
      type: apiKey
      in: header
      name: X-Domino-Api-Key
    BearerAuthentication:
      type: apiKey
      name: Authorization
      in: header

````

## Related topics

- [Select Domino endpoint authorization mode](/cloud/platform-capabilities/features/model-deployment/domino-endpoint-authorization.md)
- [Change who can discover and invoke a Model API](/api-reference/model-apis/change-who-can-discover-and-invoke-a-model-api.md)
- [Read who can discover and invoke a Model API](/api-reference/model-apis/read-who-can-discover-and-invoke-a-model-api.md)
- [Domino skills reference](/cloud/reference/skills.md)
