API keys
An API key decides who can call, which models they can call and how much they can spend. You can create several keys per account. Use one per app or environment so you can stop just one when something goes wrong.
Viewing the full key
- The full key starts with
key_and is shown right after it is created or reset. - Later, click Reveal on the Keys page and enter your login password to see it again. Every reveal asks for the password. Five wrong attempts within 5 minutes lock reveals for 15 minutes.
- Revoked keys cannot be revealed. Administrators cannot see your full key either.
Pause, reset and revoke
| Action | Effect |
|---|---|
| Pause / resume | New requests with a paused key are refused; resuming works immediately |
| Reset | Issues a new secret with the same prefix; the old secret stops working at once. Requires your login password |
| Revoke | Disables the key permanently |
Paused, expired, revoked and mistyped keys all return the same error, auth.invalid_key (HTTP 401). Keys are checked when a request starts, so calls already in progress finish and are billed normally.
Restricting a key
When creating or editing a key, you can set its own:
- Allowed models: only the listed models can be called; empty means all models. Calling another model returns
auth.forbidden(HTTP 403). - Daily / monthly spend limit in the instance currency. The check uses the estimated cost before each call, so one call may push actual spend slightly past the limit; later calls are refused with
key.spend_limit(shown asbilling.key_limit_exceededin the OpenAI format). Days and months roll over in the instance timezone. - IP allowlist of single IPs or CIDR ranges. Requests from elsewhere return
key.ip_denied(HTTP 403). - Expiry time, after which the key stops working.
Security tips
- Keep keys in server-side environment variables or a secret manager. Never ship them in frontend code, mobile apps or public repositories.
- Send keys in headers only (
Authorization: Bearer, orx-api-keyfor Anthropic). Keys in URL parameters are always rejected. - If you suspect a leak, reset or revoke the key first, then check that key's calls in usage.
FAQ
- I forgot to save my key. What now?
- Click Reveal on the Keys page and enter your login password to see the full key again. Revoked keys cannot be revealed.
- What is the difference between reset and revoke?
- Reset issues a new secret and invalidates the old one at once, keeping the key and its limits. Revoke disables the key permanently.
- Does pausing a key stop requests already running?
- No. Keys are checked when a request starts, so running requests finish and are billed; only new requests are refused.
- Why did spend go slightly over the limit?
- The limit is checked against each call's estimated cost before it runs, so one call's actual cost can push the total a little past it. Later calls are refused.