# Asset library Volcengine-compatible endpoint

Volcengine Ark Open API format compatible entry point for the asset
library. Point the base URL at XRToken and the request path, parameters,
and response stay identical to the official Volcengine API. Authenticate
with an XRToken API key (`Authorization: Bearer tr-xxx` or
`x-api-key: tr-xxx`) — no AK/SK required.

The `Action` query parameter selects the operation. All of these use
the official `POST /?Action=...` path:
- `Action=CreateAssetGroup`: create an asset group. `ProjectName` is
  optional: when omitted, the gateway project (currently `xrtoken`)
  is used automatically; when explicitly provided (including
  `default`), the value is passed through as-is.
- `Action=CreateAsset`: create an asset. `ProjectName` is optional:
  when omitted, the gateway project (currently `xrtoken`) is used
  automatically; when explicitly provided (including `default`), the
  value is passed through as-is. `Name` is optional too.
- `Action=GetAssetGroup`: query an asset group, body
  `{"Id": "group-xxx"}`.
- `Action=GetAsset`: query an asset, body `{"Id": "asset-xxx"}`.
- `Action=ListAssetGroups`: list asset groups.
- `Action=ListAssets`: list assets.
- `Action=UpdateAssetGroup`: update an asset group.
- `Action=UpdateAsset`: update an asset.
- `Action=DeleteAssetGroup`: delete an asset group.
- `Action=DeleteAsset`: delete an asset.
- `Action=CreateVisualValidateSession`: create a real-person
  verification session.
- `Action=GetVisualValidateResult`: query a real-person
  verification result.

Responses use the official Volcengine `ResponseMetadata` / `Result`
envelope and keep the asset library's tenant isolation (you can only
operate on assets under groups you own).

## POST /

> Asset library Volcengine-compatible endpoint

Volcengine Ark Open API format compatible entry point for the asset
library. Point the base URL at XRToken and the request path, parameters,
and response stay identical to the official Volcengine API. Authenticate
with an XRToken API key (`Authorization: Bearer tr-xxx` or
`x-api-key: tr-xxx`) — no AK/SK required.

The `Action` query parameter selects the operation. All of these use
the official `POST /?Action=...` path:
- `Action=CreateAssetGroup`: create an asset group. `ProjectName` is
  optional: when omitted, the gateway project (currently `xrtoken`)
  is used automatically; when explicitly provided (including
  `default`), the value is passed through as-is.
- `Action=CreateAsset`: create an asset. `ProjectName` is optional:
  when omitted, the gateway project (currently `xrtoken`) is used
  automatically; when explicitly provided (including `default`), the
  value is passed through as-is. `Name` is optional too.
- `Action=GetAssetGroup`: query an asset group, body
  `{"Id": "group-xxx"}`.
- `Action=GetAsset`: query an asset, body `{"Id": "asset-xxx"}`.
- `Action=ListAssetGroups`: list asset groups.
- `Action=ListAssets`: list assets.
- `Action=UpdateAssetGroup`: update an asset group.
- `Action=UpdateAsset`: update an asset.
- `Action=DeleteAssetGroup`: delete an asset group.
- `Action=DeleteAsset`: delete an asset.
- `Action=CreateVisualValidateSession`: create a real-person
  verification session.
- `Action=GetVisualValidateResult`: query a real-person
  verification result.

Responses use the official Volcengine `ResponseMetadata` / `Result`
envelope and keep the asset library's tenant isolation (you can only
operate on assets under groups you own).

### Authentication

`Authorization: Bearer tr-xxx`

### Query Parameters

- **Action** `string` **(required)**  
  Operation:
- `CreateAssetGroup` -- create an asset group
- `CreateAsset` -- create an asset
- `GetAssetGroup` -- query an asset group
- `GetAsset` -- query an asset
- `ListAssetGroups` -- list asset groups
- `ListAssets` -- list assets
- `UpdateAssetGroup` -- update an asset group
- `UpdateAsset` -- update an asset
- `DeleteAssetGroup` -- delete an asset group
- `DeleteAsset` -- delete an asset
- `CreateVisualValidateSession` -- create a real-person verification session
- `GetVisualValidateResult` -- query a real-person verification result

- **Version** `string`  
  API version, defaults to `2024-01-01`.

### Request Body

Content-Type: `application/json`

### Response

### Error Codes

- `400`: 
- `401`: 
- `403`: Forbidden (not trusted creator / enterprise not verified / group not owned by the caller)
- `404`: Asset not found or does not belong to the current user
- `429`: 
- `502`:
