How to hit the GigaChat (Sber) API

GigaChat is Sber's family of language models. Its servers use a certificate from the Russian Trusted Root CA, which browsers and most operating systems don't trust — so these calls won't run from a browser, including PostTaco. With curl, install the Russian Trusted Root CA or pass it via --cacert.

Authentication

Get an authorization key in the Sber developer studio, exchange it for an access token (valid 30 minutes) with the first call, then send that token as a Bearer token. RqUID must be a fresh UUID for each token request.

Full reference: https://developers.sber.ru/docs/ru/gigachat/api/reference/rest/gigachat-api

Get an access token

scope is GIGACHAT_API_PERS for individuals, GIGACHAT_API_B2B or GIGACHAT_API_CORP for businesses.

curl -X POST https://ngw.devices.sberbank.ru:9443/api/v2/oauth \
  -H "Authorization: Basic {{GIGACHAT_AUTH_KEY}}" \
  -H "RqUID: {{UUID}}" \
  -H "Accept: application/json" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d scope=GIGACHAT_API_PERS
Run in PostTaco

Chat completion

curl -X POST https://gigachat.devices.sberbank.ru/api/v1/chat/completions \
  -H "Authorization: Bearer {{GIGACHAT_ACCESS_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{"model": "GigaChat", "messages": [{"role": "user", "content": "Привет! Что ты умеешь?"}]}'
Run in PostTaco