コンテンツにスキップ

使用例

cURLでの使用例

サーバー用APIキー認証を使用した例

readonly / fullaccess のキーをサーバーから X-Api-Key ヘッダーで送信します。show_all=true や削除には fullaccess が必要です。embedded では以下の一般APIを呼び出せません。

Storage APIの 12345 はFilmaFile ID、Player・DASH・HLSの 12345 はMediafile IDです。それぞれ実際のIDに置き換えてください。

# ファイル一覧取得(1ページ目、10件ずつ、公開ファイルのみ)
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/storage?page=1&per_page=10"

# ファイル一覧取得(全ファイル表示 - fullaccess権限のみ)
curl -H "X-Api-Key: YOUR_FULLACCESS_KEY" "https://filma.biz/filmaapi/storage?page=1&per_page=10&show_all=true"

# ファイル再生情報取得(公開ファイルのみ)
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/storage/12345"

# ファイル再生情報取得(全ファイル表示 - fullaccess権限のみ)
curl -H "X-Api-Key: YOUR_FULLACCESS_KEY" "https://filma.biz/filmaapi/storage/12345?show_all=true"

# ファイルメタデータ取得(公開ファイルのみ)
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/storage/metadata/12345"

# ファイルメタデータ取得(全ファイル表示 - fullaccess権限のみ)
curl -H "X-Api-Key: YOUR_FULLACCESS_KEY" "https://filma.biz/filmaapi/storage/metadata/12345?show_all=true"

# フォルダ一覧取得
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/storage/folders"

# フォルダ詳細取得
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/storage/folders/100"

# ファイル削除
curl -H "X-Api-Key: YOUR_FULLACCESS_KEY" -X DELETE "https://filma.biz/filmaapi/storage/12345"

# プレイヤー表示(公開ファイルのみ - デフォルト)
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/player/12345"

# プレイヤー表示(全ファイル表示 - fullaccess権限のみ)
curl -H "X-Api-Key: YOUR_FULLACCESS_KEY" "https://filma.biz/filmaapi/player/12345?show_all=true"

# DASH配信(公開ファイルのみ)
curl -H "X-Api-Key: YOUR_READONLY_KEY" "https://filma.biz/filmaapi/dash/12345"

# DASH配信(全ファイル表示 - fullaccess権限のみ)
curl -H "X-Api-Key: YOUR_FULLACCESS_KEY" "https://filma.biz/filmaapi/dash/12345?show_all=true"

サーバー用キーから取得したJWTを使用する例

以下は readonly / fullaccess のJWT向けです。ブラウザに渡す場合は、最初のJWT取得処理をサーバー側で実行してください。

# 1. サーバー側で汎用JWTを取得(mediafile_idを省略)
curl -X POST "https://filma.biz/filmaapi/token" \
  -H "X-Api-Key: YOUR_READONLY_KEY" \
  -H "Content-Type: application/json"

# 2. 発行されたJWTトークンを使用してAPIアクセス(Authorization header)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/storage?page=1&per_page=10"

# 2-2. または、取得したJWTをCookieに明示してアクセス
curl -H "Cookie: filmajwt=eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/storage?page=1&per_page=10"

# 3. ファイル再生情報取得(JWT認証)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/storage/12345"

# 4. ファイルメタデータ取得(JWT認証)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/storage/metadata/12345"

# 5. プレイヤー表示(JWT認証)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/player/12345"

# 6. DASH配信(JWT認証)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/dash/12345"

# 7. HLS配信(JWT認証)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/hls/12345"

# 8. 有効期間内のトークンをリフレッシュ(embeddedは不可)
curl -X POST "https://filma.biz/filmaapi/token/refresh" \
  -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  -H "Content-Type: application/json"

# 9. トークン情報取得(embeddedは不可)
curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/token"

管理画面での自動JWT認証(Cookie)

curl -H "Cookie: filmajwt=eyJhbGciOiJIUzI1NiJ9..." \
  "https://filma.biz/filmaapi/storage"

embeddedキーで公開動画を再生する例

# 1. 公開動画のMediafile IDを指定して再生JWTを取得
curl -X POST "https://filma.biz/filmaapi/token?api_key=YOUR_EMBEDDED_KEY" \
  -d "mediafile_id=12345&playback_token=true"

# 2. 応答のtokenを使ってプレイヤーを取得
curl "https://filma.biz/filmaapi/player/12345?jwt=YOUR_PLAYBACK_JWT"

embedded では expires_in、jwt_expires_at、show_all を指定できません。JWTはCookieに設定されず、ファイル一覧・メタデータ取得やJWT更新にも使用できません。管理画面で生成される埋め込みHTMLは、対応するプレイヤーがキーをJWTへ交換します。APIキー付きの古いiframe URLを直接使う方式とは異なります。

JavaScriptでの使用例

サーバー側でJWTを取得

以下はfetchを使えるサーバー環境向けです。apiKey にはサーバーで保管した readonly キーを渡し、取得したJWTを必要な利用者に返します。会員認証や視聴権の確認はアプリケーションの要件に合わせて行ってください。

function getFilmaToken(apiKey) {
  return fetch('https://filma.biz/filmaapi/token', {
    method: 'POST',
    headers: { 'X-Api-Key': apiKey }
  }).then(response => {
    if (!response.ok) {
      throw new Error(`JWT取得に失敗しました: ${response.status}`);
    }
    return response.json(); // token、expires_atなどを返す
  });
}

ブラウザ側でJWTを使用

showFiles にアプリケーションのサーバーから受け取ったJWTを渡します。埋め込み用JWTでは一覧取得できません。

function showFiles(token) {
  const apiBase = 'https://filma.biz/filmaapi';
  const headers = { Authorization: `Bearer ${token}` };

  function getJson(path) {
    return fetch(`${apiBase}${path}`, { headers }).then(response => {
      if (!response.ok) {
        throw new Error(`API呼び出しに失敗しました: ${response.status}`);
      }
      return response.json();
    });
  }

  return getJson('/storage?page=1&per_page=20').then(list => {
    console.log('総件数:', list.pagination.total_count);

    // 12345はFilmaFile ID、100はフォルダIDに置き換える
    return Promise.all([
      getJson('/storage/12345'),
      getJson('/storage/metadata/12345'),
      getJson('/storage/folders'),
      getJson('/storage/folders/100')
    ]);
  }).then(([player, metadata, folders, folder]) => {
    // player.urlには動画限定JWTが含まれる。既存のiframeに設定する例
    const frame = document.getElementById('filma-player');
    if (frame) {
      frame.src = player.url;
    }
    return { player, metadata, folders, folder };
  });
}

<iframe id="filma-player" title="動画プレイヤー" allowfullscreen></iframe> をページに配置すると、取得した再生URLを設定できます。iframeには認証ヘッダーを追加できないため、JWT付きURLを使用します。JWTも有効期間内は認証情報となるので、URLやトークンを不用意に共有・記録しないでください。

JWTサンプル は、動作確認のためにブラウザ内で readonly キーを使ってJWTを取得しています。通常の運用ではキーをサーバーに保管し、JWT取得処理をサーバーへ移してください。取得したJWTを使う一覧表示・再生処理は、その構成でも利用できます。

動画埋め込みサンプル は埋め込みHTMLの使用例です。template-no-auth という公開URLは維持していますが、以前のAPI一覧取得コードは廃止しています。