Reference

API reference

Base URL: https://getmorphis.com. All requests use HTTPS and JSON. The endpoint allows cross-origin requests, so it can be called directly from a browser (this is what the SDK does).

Authentication

Every request carries a tenant API key in the JSON body as apiKey. Keys look like mph_live_…, are created in the dashboard under API Keys, and are shown only once.

auth.sh
curl -X POST https://getmorphis.com/api/generate-ui   -H "Content-Type: application/json"   -d '{
    "apiKey": "mph_live_...",
    "intent": "show a churn-risk table",
    "contextData": { "customers": 12, "churn": 2.4 },
    "theme": "light"
  }'
Treat keys like passwords: keep them out of public repositories. Deleting a key in the dashboard revokes it immediately because every request is re-validated.

POST /api/generate-ui

Generate a sanitized UI component from a prompt and context data.

Request body (platform route)

request.json
{
  "apiKey": "mph_live_...",            // required — tenant API key
  "intent": "show a churn-risk table",  // required — what to generate (1–2000 chars)
  "contextData": { "mrr": 5400 },       // optional — object with live data (max 50 KB)
  "theme": "light"                      // optional — "light" | "dark" (default "light")
}

Response 200

response.json
{
  "html": "<!DOCTYPE html><html>…</html>",  // self-contained document: markup + styles
  "css": ".morphis-root { … }",             // the same styles, separately (LLM responses only)
  "metadata": {
    "generationTime": 5120,                 // ms, wall clock
    "tokensUsed": 2040,                     // LLM tokens (0 when source = "fallback")
    "sanitized": true,                      // output passed the HTML/CSS sanitizer
    "model": "openai/gpt-oss-120b",         // model that produced the result
    "source": "llm"                         // "llm" | "fallback"
  }
}

Render html inside an iframe with sandbox="allow-scripts" and srcdoc (the SDK does this for you). source: "fallback" means the AI engine was unavailable and a built-in template was returned instead of failing the request.

Error responses

CodeMeaningFix
400Invalid JSON body, missing apiKey or intent, intent over 2,000 chars, or contextData not an objectCheck the request shape against the example above.
401Invalid API keyConfirm the key is correct and has not been deleted.
413contextData larger than 50 KBSend only the fields the UI needs.
429Rate limit or monthly quota exceededRespect the Retry-After header; upgrade your plan or wait for the next month.
500Unexpected server errorRetry with exponential backoff; contact support if it persists.

Rate limits & quotas

  • Each API key is limited to 30 requests per minute; excess requests get a 429 with a Retry-After header (seconds).
  • Repeated invalid-key attempts from one IP address are blocked temporarily (429).
  • Monthly quota is per workspace: 1,000 generations/month on the free plan. Exceeding it returns 429 until the next month.
  • Generation usually takes a few seconds; allow up to 60 seconds before timing out on your side.
  • Every response includes metadata.source so you can monitor AI vs fallback usage.
Ready to try it? Open the live Playground for zero-config testing.