Authentication
Authentication
All model endpoints authenticate with an API key. Create keys on the API Keys page of the dashboard; they start with sk-.
Sending the key
Use any one of these headers:
Keys in URL query parameters (?key= or ?api_key=) are rejected with 400 api_key_in_query_deprecated. URLs end up in logs, browser history and proxies, which makes them easy to leak.
Key restrictions
Each key can be configured in the dashboard with:
Group: which models and prices apply; IP allowlist / blocklist: allow or block specific IPs; Quota and expiry: requests are rejected once exceeded or expired.
Authentication errors
See Errors for the full list.