curl --request POST \
--url https://api.samsa.ai/public/v1/images/variations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"image": {
"image_id": "123e4567-e89b-12d3-a456-426614174000"
}
}
'import requests
url = "https://api.samsa.ai/public/v1/images/variations"
payload = { "image": { "image_id": "123e4567-e89b-12d3-a456-426614174000" } }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({image: {image_id: '123e4567-e89b-12d3-a456-426614174000'}})
};
fetch('https://api.samsa.ai/public/v1/images/variations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.samsa.ai/public/v1/images/variations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'image' => [
'image_id' => '123e4567-e89b-12d3-a456-426614174000'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.samsa.ai/public/v1/images/variations"
payload := strings.NewReader("{\n \"image\": {\n \"image_id\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.samsa.ai/public/v1/images/variations")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"image\": {\n \"image_id\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.samsa.ai/public/v1/images/variations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"image\": {\n \"image_id\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "pending",
"estimated_credits": 5
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}Générer des variations
Soumets un job de variations — une image source, éventuellement guidée — et récupère un id de job.
curl --request POST \
--url https://api.samsa.ai/public/v1/images/variations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"image": {
"image_id": "123e4567-e89b-12d3-a456-426614174000"
}
}
'import requests
url = "https://api.samsa.ai/public/v1/images/variations"
payload = { "image": { "image_id": "123e4567-e89b-12d3-a456-426614174000" } }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({image: {image_id: '123e4567-e89b-12d3-a456-426614174000'}})
};
fetch('https://api.samsa.ai/public/v1/images/variations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.samsa.ai/public/v1/images/variations",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'image' => [
'image_id' => '123e4567-e89b-12d3-a456-426614174000'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.samsa.ai/public/v1/images/variations"
payload := strings.NewReader("{\n \"image\": {\n \"image_id\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.samsa.ai/public/v1/images/variations")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"image\": {\n \"image_id\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.samsa.ai/public/v1/images/variations")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"image\": {\n \"image_id\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "pending",
"estimated_credits": 5
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}{
"error": {
"type": "authentication_error",
"code": "invalid_api_key",
"message": "The provided API key is invalid, expired, or revoked.",
"request_id": "8f14e45fceea167a5a36dedd4bea2543",
"param": "aspect_ratio"
}
}image source. L’appel renvoie
202 Accepted avec un id de job ; interroge
GET /images/variations/{id} pour le
résultat. L’image prend exactement un de image_id, url ou
base64 + mime_type. Requiert le scope images.transform.
Exemple : une source par mode
curl -X POST https://api.samsa.ai/public/v1/images/variations \
-H "Authorization: Bearer $SAMSA_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "image": { "image_id": "123e4567-e89b-12d3-a456-426614174000" } }'
curl -X POST https://api.samsa.ai/public/v1/images/variations \
-H "Authorization: Bearer $SAMSA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"image": { "url": "https://cdn.example.com/photo.png" },
"target": "object",
"creativity": "subtle",
"num_outputs": 4,
"variation_instructions": "Try different background colors"
}'
curl -X POST https://api.samsa.ai/public/v1/images/variations \
-H "Authorization: Bearer $SAMSA_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"image": { "base64": "iVBORw0KGgoAAAANSUhEUg...", "mime_type": "image/png" },
"preservation_instructions": "Keep the product shape unchanged",
"webhook_url": "https://example.com/webhooks/samsa"
}'
202 est le handle de job asynchrone :
{
"id": "c4d5e6f7-8a9b-4c1d-2e3f-4a5b6c7d8e9f",
"status": "pending",
"estimated_credits": 5
}
image. target — ce que les variations
peuvent changer — est everything (défaut), person, object ou scene.
creativity est subtle ou creative (défaut). variation_instructions (quoi
changer) et preservation_instructions (quoi conserver) sont du texte libre
optionnel, ≤ 2000 caractères chacun. num_outputs (1 à 4) vaut 1 par défaut et
chaque sortie (output) est facturée. Il n’y a pas de paramètre resolution — la
résolution de sortie est héritée de la source.Credits
Chaque sortie (output) coûte5 credits en 1K, en fonction du palier de résolution
de l’image source (1K ×1, 2K ×2, 4K ×4) et multiplié par num_outputs.
Voir Tarifs.
Erreurs
| Statut | Code | Quand |
|---|---|---|
402 | insufficient_credits / insufficient_team_credits / insufficient_unallocated_credits | Le solde que ce credential peut dépenser est en dessous du coût du job. Les organisations avec au moins une équipe active reçoivent les codes liés aux équipes à la place de insufficient_credits (sauf les organisations système exemptées du budgeting par équipe). Une défaillance opérationnelle dans la déduction elle-même peut néanmoins renvoyer le générique insufficient_credits, quel que soit le régime. |
402 | subscription_inactive | L’organisation n’a aucun abonnement utilisable. |
403 | missing_scope | La clé n’a pas le scope images.transform. |
404 | not_found | L’image_id source est inconnu ou n’appartient pas au créateur de la clé — une image créée par un autre membre de ton organisation renvoie aussi un 404. |
422 | validation_error | Zéro/plusieurs modes source, target/creativity invalide ou instructions trop longues. |
429 | rate_limited / too_many_active_jobs | Fenêtre de débit par clé ou plafond de concurrence par organisation dépassé. |
Autorisations
Organization API key as a bearer token: Authorization: Bearer samsa_sk_....
Corps
POST /images/variations body (SAM-816 / S8.4 — ADR §8, §10).
Generate creative variations of ONE source image (the app's Gemini 3 Pro
variations flow). The source is exactly one of image_id (an image in your
organization's context), an https url, or base64+mime_type. The output
resolution is inherited from the source (there is no resolution param);
each output is billed at 5 x resolution_multiplier credits (1K:1x, 2K:2x,
4K:4x) where the multiplier is the source image's resolution tier. target
and creativity are lowercase public aliases of the internal Gemini
variation controls; num_outputs defaults to 1 (the app default is 4).
The source image: exactly one of image_id, url, or base64+mime_type.
Show child attributes
Show child attributes
What the variations may change: everything (default), person, object, or scene.
everything, person, object, scene "everything"
How far the variations may deviate from the source: subtle or creative (default).
subtle, creative "creative"
Optional free-text guidance for WHAT to change (<= 2000 chars).
2000"Try different background colors and lighting"
Optional free-text guidance for WHAT to keep (<= 2000 chars).
2000"Keep the product label and shape unchanged"
Number of variations to generate (1-4). Defaults to 1 (the app default is 4); each output is billed.
1 <= x <= 41
Optional https webhook notified once on terminal status (signed per the webhook signature scheme; see the webhooks docs).
"https://example.com/webhooks/samsa"
Réponse
Successful Response
Shared 202 body for the transform-op submits (SAM-813 / S8 wave).
Every POST /images/<op> returns the async job handle
{id, status, estimated_credits}. The initial status is pending (the
job is queued), with ONE exception: background-removals and
vectorizations answer an owned-image_id cache hit (a ready result
already exists for that image) with status: "completed" and
estimated_credits: 0 — no new job is queued, the completed webhook
event is emitted immediately for a supplied webhook_url, and the result
is already available from the op's GET .../{id} endpoint. The other
transform ops (img2img, variations, resizes, upscales) always
start pending.
The job id — poll the op's GET .../{id} endpoint.
Initial status: pending (job queued — enter the polling flow), or completed with estimated_credits: 0 when background-removals / vectorizations serve an owned-image cache hit (the result is immediately available).
pending, processing, completed, failed, cancelled "pending"
Credits this job is expected to cost — 0 on a cache-hit completed response.
5

