Authorization: Bearer <API_KEY> header. Create and manage keys in Dashboard → Settings → API Keys. Give each project, teammate or end customer its own key, scoped to exactly what it needs: what it may do, for how long, how much it may spend, and where it may be called from.
Key roles
Every key has one of two roles, chosen when the key is created. The role cannot be changed later — to change it, create a new key.- API key — runs inference (images, video, audio, …). It has no access to account billing or to other keys: for example, Check Balance returns
403insufficient_permissions. Use it for applications, integrations and keys you hand out per project or per end customer. - ADMIN key — full access to the account: inference, account billing and key management.
Key restrictions
Each key can carry any combination of the restrictions below — set them when creating the key or change them later. Changes apply from the next request; there is no need to recreate the key.
Good to know about the spend limit:
- Changing the limit does not reset the counter. Raising a limit from $50 to $100 after spending $50 leaves $50 of headroom. Lowering it below the amount already spent blocks the key until the window resets.
- A limit is a ceiling, not a budget. A key never spends more than the account balance, and the limits of all keys together may exceed it.
- A refunded (failed) job gives its cost back to the key’s limit.
Number of keys
An account can have up to 100 active keys. Expired, disabled and deleted keys do not count — disabling a key frees its slot immediately.Error codes
Key-related rejections carry a machine-readablecode field next to message: