Authentication and API keys
Create, use, limit, rotate and protect your API keys.
Create an API key
- Sign in, open the API Keys page of the console and give the key a name that says what it is for.
- Set any limits you want (requests per minute, budgets, allowlists); you can change them later.
- The new key appears in the list; click Copy to get the full key (it starts with
sk-) and keep it somewhere safe, such as an environment variable on your server.
Send the key with each request
OpenAI-compatible endpoints take an Authorization: Bearer header; the Anthropic endpoints take x-api-key and also accept Authorization: Bearer. Keep the key in an environment variable, not in your code.
Authorization: Bearer YOUR_API_KEY
Put limits on a key
Each key can have its own limits, independent of the others:
| Setting | What it does |
|---|---|
| Requests per minute | The most requests this key may send in a minute. |
| Daily budget | The most this key may spend per day (UTC), in US dollars. |
| Total limit | The most this key may spend in total, in US dollars; good for automation that must not run away. |
| Model allowlist | This key may call only the models listed. |
| IP allowlist | Only requests from the listed IPs or ranges are accepted. |
Disable and rotate
- Create a new key and switch your code over to it.
- Once the new key is working, disable the old one in the console. It takes effect at once; requests with the old key then get 401.
- If you think a key leaked, disable it first, then create a new one.
Keeping keys safe
- Keep keys on your server. Never put them in a web page, an app or a public repository.
- Use a separate key per app and per environment, so a problem means disabling just that one.
- Give keys used by automation or third-party tools a budget or total limit.
- If your servers have fixed IPs, turn on the IP allowlist.
The balance belongs to the account
All keys of an account share one balance. GET /v1/usage with any key returns the account's balance and spend.