Production Readiness
What the DeepFrame API documents today, a launch checklist, and enterprise questions to confirm separately.
Use this page to decide whether an integration is ready for a controlled production evaluation. This portal documents the DeepFrame API's technical behavior, but it does not publish every commercial or enterprise commitment.
Alpha Is Not A Production Commitment
/api/v1alpha1 has no compatibility promise. This portal does not publish an SLA, support response time, regional hosting commitment, or commercial entitlement. Confirm those requirements separately before relying on the API in production.
What The Current Contract Covers
| Area | Documented behavior |
|---|---|
| Access | Workspace opt-in, Public API Alpha keys, and operation-level permissions. |
| Workspace isolation | The API derives workspace identity from the key. Cross-workspace resources return the same 404 shape as missing resources. |
| Safe writes | Supported state-changing POST operations accept Idempotency-Key; matching retries return the original response, except a completed webhook creation retry returns 409 conflict and cannot replay its signing secret. |
| Capacity signals | Responses expose rate-limit headers. A 429 response includes Retry-After. |
| Long-running work | Videos, queries, and runs expose explicit states that can be polled. Terminal events can also be delivered by webhook. |
| Failure handling | RFC 9457 problem bodies include a stable type and a request_id; asynchronous failures use a structured error. |
| Evidence and uncertainty | Findings and answers preserve result state, limitations, and reviewable evidence instead of turning uncertainty into a clean pass. |
| Change visibility | The alpha stability policy, deprecation headers, and changelog describe contract changes. |
Follow Authentication, Conventions, Errors, Webhooks, and Policies for the exact behavior.
Launch Checklist
- Keep API keys in a server-side secret manager. Never send them to browser code.
- Use a dedicated key with only the permissions the integration needs.
- Confirm that the Public API Alpha opt-in is enabled for the intended workspace.
- For a supported state-changing
POSTrequest, preserve the same idempotency key and request body when retrying it. - Bound retries. Honor
Retry-Afterfor 429 and use backoff with jitter for retryable 503 responses. - Treat
completed,failed, andcanceledas distinct terminal outcomes. For video search, requirestatus=completedbefore running analysis. - Verify webhook signatures against the raw body and reject stale or replayed deliveries.
- Log
request_idwith your own correlation identifier, without logging secrets or sensitive request bodies. - Preserve
found,not_found,uncertain, andnot_checked, plus limitations and evidence, in downstream decisions. - Test one success, one validation failure, one permission failure, one rate-limit response, and one asynchronous failure before launch.
Confirm These Enterprise Requirements
The current portal does not state answers for the following items. Record an explicit answer for each one that matters to your organization:
- Commercial availability, quotas, and expected workload limits.
- Availability objectives, support hours, response targets, and escalation route.
- Processing and storage regions, data residency, and cross-border transfer requirements.
- Retention periods, offboarding deletion, legal hold, and backup handling.
- Key-owner governance, rotation frequency, employee offboarding, and audit requirements.
- Security, privacy, procurement, and vendor-risk evidence required by your organization.
- Change-notice expectations while the API remains alpha.
Do not infer an enterprise commitment from an HTTP response or from behavior observed during an evaluation.
Get The Missing Answers
Use the contact agreed for your DeepFrame evaluation to confirm the unresolved items above. If you do not have an existing contact, visit deepframe.cloud for the current contact options. Include the workspace, intended workload, required region, and launch date; do not include API keys or customer data.
When those answers are recorded, run the Quickstart in a non-production workspace and use the API reference to verify every operation your integration calls.