Skip to main content

Create and copy

and create a key with the model permissions, spending limit, and expiry your application needs. Use the copy button to retrieve the full key: a displayed prefix is not a credential. Revoked keys cannot make new requests.

Authentication by protocol

Use your Codeflare key, not a provider’s upstream credential. A console session cookie does not authenticate gateway API calls.

Storage and rotation

Keep keys in server-side environment variables or a secret manager. Do not include them in browser code, source control, or shared screenshots. To rotate, create a replacement, update and verify your application, then revoke the old key. For 401 responses, check key status, expiry, and authentication format. For 403, check model permissions.
Both the key’s spending limit and the account’s available balance affect admission. See Troubleshooting if the request budget is insufficient.