Skip to main content
Every request is authenticated with an API key sent in the Authorization: Bearer <API_KEY> header. Create and manage keys in Dashboard → Settings → API Keys. Give each project, teammate or end customer its own key, scoped to exactly what it needs: what it may do, for how long, how much it may spend, and where it may be called from.

Key roles

Every key has one of two roles, chosen when the key is created. The role cannot be changed later — to change it, create a new key.
  • API key — runs inference (images, video, audio, …). It has no access to account billing or to other keys: for example, Check Balance returns 403 insufficient_permissions. Use it for applications, integrations and keys you hand out per project or per end customer.
  • ADMIN key — full access to the account: inference, account billing and key management.
Keys created before roles were introduced are ADMIN keys, so existing integrations keep working unchanged. If a key only needs to run inference, replace it with a new API key and delete the old one.
Treat an ADMIN key like a password: keep it server-side and never ship it in client apps. Use API keys everywhere else.

Key restrictions

Each key can carry any combination of the restrictions below — set them when creating the key or change them later. Changes apply from the next request; there is no need to recreate the key. Good to know about the spend limit:
  • Changing the limit does not reset the counter. Raising a limit from $50 to $100 after spending $50 leaves $50 of headroom. Lowering it below the amount already spent blocks the key until the window resets.
  • A limit is a ceiling, not a budget. A key never spends more than the account balance, and the limits of all keys together may exceed it.
  • A refunded (failed) job gives its cost back to the key’s limit.
Rejected requests — expired, disabled, outside the allowlist or over the limit — do not create a job and are not charged.

Number of keys

An account can have up to 100 active keys. Expired, disabled and deleted keys do not count — disabling a key frees its slot immediately.

Error codes

Key-related rejections carry a machine-readable code field next to message: