Fetch a meal photo
curl --request GET \
--url https://app.skcal.fit/api/nutrition/photo/{key} \
--cookie __Secure-better-auth.session_token=import requests
url = "https://app.skcal.fit/api/nutrition/photo/{key}"
headers = {"cookie": "__Secure-better-auth.session_token="}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {cookie: '__Secure-better-auth.session_token='}};
fetch('https://app.skcal.fit/api/nutrition/photo/{key}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.skcal.fit/api/nutrition/photo/{key}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_COOKIE => "__Secure-better-auth.session_token=",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.skcal.fit/api/nutrition/photo/{key}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("cookie", "__Secure-better-auth.session_token=")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.skcal.fit/api/nutrition/photo/{key}")
.header("cookie", "__Secure-better-auth.session_token=")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.skcal.fit/api/nutrition/photo/{key}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["cookie"] = '__Secure-better-auth.session_token='
response = http.request(request)
puts response.read_body"<string>"{
"error": "weightKg must be 9-320 kg",
"detail": "upstream model returned 500"
}Nutrition
Fetch a meal photo
Streams a stored meal photo from object storage. The key is owner-prefixed, so callers can only read their own photos. Note that the key contains slashes.
GET
/
api
/
nutrition
/
photo
/
{key}
Fetch a meal photo
curl --request GET \
--url https://app.skcal.fit/api/nutrition/photo/{key} \
--cookie __Secure-better-auth.session_token=import requests
url = "https://app.skcal.fit/api/nutrition/photo/{key}"
headers = {"cookie": "__Secure-better-auth.session_token="}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {cookie: '__Secure-better-auth.session_token='}};
fetch('https://app.skcal.fit/api/nutrition/photo/{key}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.skcal.fit/api/nutrition/photo/{key}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_COOKIE => "__Secure-better-auth.session_token=",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.skcal.fit/api/nutrition/photo/{key}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("cookie", "__Secure-better-auth.session_token=")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.skcal.fit/api/nutrition/photo/{key}")
.header("cookie", "__Secure-better-auth.session_token=")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.skcal.fit/api/nutrition/photo/{key}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["cookie"] = '__Secure-better-auth.session_token='
response = http.request(request)
puts response.read_body"<string>"{
"error": "weightKg must be 9-320 kg",
"detail": "upstream model returned 500"
}Authorizations
sessionCookiebearerApiKey
Better Auth session. Signing in (Google or email magic link) sets an HttpOnly session cookie that scopes every request to that account. The web app and CLI use this; agents use the OAuth 2.1 flow of the MCP server.
Path Parameters
Owner-prefixed object key, e.g. user@example.com/2026-06-29/<uuid>.
Response
The image bytes.
The response is of type file.