lk_ and pass in the Authorization header on every request:
Keys belong to an organization
Every API key is scoped to a single organization. The key authenticates the request and pins it to that org, there’s no need to send an extraX-Org-Slug header.
The credits, runs, VMs, and deployments associated with the request are all billed and accessed through the key’s org.
If you belong to several orgs, create a separate key in each one for the scripts that act on its behalf.
API keys vs JWT tokens
The platform supports two token types:
JWT users can act on any org they’re a member of by sending
X-Org-Slug: <slug>; with an API key, the org is fixed by the key itself.
Lifecycle
API keys can be:- Created with a name and an optional expiration date. Names are unique among the org’s live keys.
- Regenerated to issue a fresh secret while keeping the key’s name, org, and expiration. Rotate a key without touching the scripts that reference it by name. Regenerating a revoked key also reactivates it.
- Revoked to disable it. Reversible: the key leaves the default Active keys view in the dashboard, keeps its name reserved, and comes back when you regenerate it.
- Deleted to remove it for good. The key disappears from every list, cannot be regenerated, and its name is free to reuse in the org. The row is kept internally for the audit trail.
Spend limits
An owner or admin can put a spend limit on a key: a cap on what that key may spend on serverless inference. Once the key has reached it, new requests with that key are refused with402 and the error code api_key_spend_limit_reached, until the limit is raised, reset or removed. Members see the limit on their own keys but cannot change it.
A limit either renews monthly, counting from the 1st of each calendar month (UTC) and starting over on the next, or is a fixed budget that counts until it is used up and stays exhausted until an owner raises or resets it. A monthly limit set in the middle of a month covers the whole month.
What to expect:
- A limit is a cap, not a reservation. Requests are still paid from the org’s balance, and the org’s own balance check comes first: a key under its limit in an org without credits is refused for the org’s reason, with the usual
402and no error code. - It is a soft limit. What a key has spent is read from the ledger, which is settled every few minutes, and a request that is already running is never cut. A key can therefore exceed its cap by a few minutes of usage before new requests are refused.
- Changes take effect within 5 minutes, like every change to a key, because the inference proxy caches key lookups.
- The spend shown next to the limit in the dashboard is the estimate from the usage page and can differ slightly from the ledger the limit is checked against.
- The minimum limit is 1 in the org’s account currency, with up to four decimal places.
Dashboard
Open API Keys in the dashboard. The page lists your active keys across every org you belong to, with filters to narrow by org and by status. Create a new key with the Create key button; the dialog defaults to the active org but you can pick any org. Each key row has three actions: regenerate (circular arrows) rotates the secret in place, revoke (the ban icon) disables the key reversibly, and delete (the trash icon) removes it for good. The Status filter switches between Active keys, Revoked keys and All keys; revoked keys carry a Revoked chip, and from there you can regenerate them to reactivate or delete them to free the name. As with creation, the new value from a regenerate is shown only once. Keys with a spend limit show it under their name: spend against the cap with a bar, amber from 80 percent and red at the cap. Owners and admins get a fourth action, spend limit (the dollar icon), to set, change, remove or, for a fixed budget, reset it. The create dialog offers the same limit.CLI
REST API
Owners and admins can call them for any key in the org; members only for keys they created, and members cannot set spend limits.
plaintext_key, store it immediately.
Every key response carries spend_limit, either null or {"amount", "currency", "renews", "since"}, where since is when the current budget started. To set a limit, pass spend_limit on create or patch it later; renews defaults to true.