> ## Documentation Index
> Fetch the complete documentation index at: https://docs.codeflare.cc/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Create separate credentials for each application and use the right authentication header.

export const ConsoleLink = ({path = "/console", children}) => <a href={"http://localhost:3001" + path} target="_blank" rel="noopener noreferrer">{children}</a>;

## Create and copy

<ConsoleLink path="/console/keys">Open API keys ↗</ConsoleLink> and create a key with the model permissions, spending limit, and expiry your application needs. Use the copy button to retrieve the full key: a displayed prefix is not a credential. Revoked keys cannot make new requests.

```bash theme={null}
export CODEFLARE_API_KEY="YOUR_CODEFLARE_KEY"
```

## Authentication by protocol

| Endpoint | Headers |
| - | - |
| Responses / Chat Completions / System One | `Authorization: Bearer YOUR_CODEFLARE_KEY` |
| Anthropic Messages | `x-api-key: YOUR_CODEFLARE_KEY` and `anthropic-version: 2023-06-01` |
| Gemini | `x-goog-api-key: YOUR_CODEFLARE_KEY` |

Use your **Codeflare key**, not a provider's upstream credential. A console session cookie does not authenticate gateway API calls.

## Storage and rotation

Keep keys in server-side environment variables or a secret manager. Do not include them in browser code, source control, or shared screenshots. To rotate, create a replacement, update and verify your application, then revoke the old key. For 401 responses, check key status, expiry, and authentication format. For 403, check model permissions.

<Note>Both the key's spending limit and the account's available balance affect admission. See [Troubleshooting](/en/troubleshooting) if the request budget is insufficient.</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.