# 素材库火山兼容端点

火山 Ark Open API 格式的素材库兼容入口。把 base URL 指向 XRToken 后，
请求路径 / 参数 / 响应与火山官方保持一致，鉴权用 XRToken API key
（`Authorization: Bearer tr-xxx` 或 `x-api-key: tr-xxx`），不需要 AK/SK。

通过 query 参数 `Action` 区分操作，路径一律是官方 `POST /?Action=...`：
- `Action=CreateAssetGroup`：创建素材组。`ProjectName` 非必填：不传时自动使用网关项目（当前 `xrtoken`）；显式传值（包括 `default`）原样透传。
- `Action=CreateAsset`：创建素材。`ProjectName` 非必填：不传时自动使用网关项目（当前 `xrtoken`）；显式传值（包括 `default`）原样透传；`Name` 可选。
- `Action=GetAssetGroup`：查询素材组，body 传 `{"Id": "group-xxx"}`。
- `Action=GetAsset`：查询素材，body 传 `{"Id": "asset-xxx"}`。
- `Action=ListAssetGroups`：列出素材组。
- `Action=ListAssets`：列出素材。
- `Action=UpdateAssetGroup`：更新素材组。
- `Action=UpdateAsset`：更新素材。
- `Action=DeleteAssetGroup`：删除素材组。
- `Action=DeleteAsset`：删除素材。
- `Action=CreateVisualValidateSession`：创建真人核验会话。
- `Action=GetVisualValidateResult`：查询真人核验结果。

响应沿用火山 `ResponseMetadata` / `Result` 信封，并保持素材库账号隔离
（只能操作自己名下的分组和素材）。

## POST /

> Asset library Volcengine-compatible endpoint

Volcengine Ark Open API format compatible entry point for the asset
library. Point the base URL at XRToken and the request path, parameters,
and response stay identical to the official Volcengine API. Authenticate
with an XRToken API key (`Authorization: Bearer tr-xxx` or
`x-api-key: tr-xxx`) — no AK/SK required.

The `Action` query parameter selects the operation. All of these use
the official `POST /?Action=...` path:
- `Action=CreateAssetGroup`: create an asset group. `ProjectName` is
  optional: when omitted, the gateway project (currently `xrtoken`)
  is used automatically; when explicitly provided (including
  `default`), the value is passed through as-is.
- `Action=CreateAsset`: create an asset. `ProjectName` is optional:
  when omitted, the gateway project (currently `xrtoken`) is used
  automatically; when explicitly provided (including `default`), the
  value is passed through as-is. `Name` is optional too.
- `Action=GetAssetGroup`: query an asset group, body
  `{"Id": "group-xxx"}`.
- `Action=GetAsset`: query an asset, body `{"Id": "asset-xxx"}`.
- `Action=ListAssetGroups`: list asset groups.
- `Action=ListAssets`: list assets.
- `Action=UpdateAssetGroup`: update an asset group.
- `Action=UpdateAsset`: update an asset.
- `Action=DeleteAssetGroup`: delete an asset group.
- `Action=DeleteAsset`: delete an asset.
- `Action=CreateVisualValidateSession`: create a real-person
  verification session.
- `Action=GetVisualValidateResult`: query a real-person
  verification result.

Responses use the official Volcengine `ResponseMetadata` / `Result`
envelope and keep the asset library's tenant isolation (you can only
operate on assets under groups you own).

### Authentication

`Authorization: Bearer tr-xxx`

### Query Parameters

- **Action** `string` **(required)**  
  Operation:
- `CreateAssetGroup` -- create an asset group
- `CreateAsset` -- create an asset
- `GetAssetGroup` -- query an asset group
- `GetAsset` -- query an asset
- `ListAssetGroups` -- list asset groups
- `ListAssets` -- list assets
- `UpdateAssetGroup` -- update an asset group
- `UpdateAsset` -- update an asset
- `DeleteAssetGroup` -- delete an asset group
- `DeleteAsset` -- delete an asset
- `CreateVisualValidateSession` -- create a real-person verification session
- `GetVisualValidateResult` -- query a real-person verification result

- **Version** `string`  
  API version, defaults to `2024-01-01`.

### Request Body

Content-Type: `application/json`

### Response

### Error Codes

- `400`: 
- `401`: 
- `403`: Forbidden (not trusted creator / enterprise not verified / group not owned by the caller)
- `404`: Asset not found or does not belong to the current user
- `429`: 
- `502`:
