Skip to main content
Use a workspace API key in an Authorization: Bearer header on every endpoint. The Anthropic-compatible routes, /v1/messages and /v1/messages/count_tokens, also accept x-api-key. So do GET /v1/models and GET /v1/models/{model}. A non-blank x-api-key wins when both headers are present on those routes.

Get a key

1

Open the model page, or Settings

Select Get API key on a page in the Model Library, or select Create API key in Settings, API keys. Both paths give you a workspace key for hosted Model APIs.
2

Copy the key

Copy it from the dialog. You can copy it again whenever you need it with the copy button on its row in Settings, API keys. The member who created a key and the workspace owner can copy it, other members and viewers cannot, and every copy is recorded in the audit log.A key created before copying was available was shown only once and exists only as a one-way digest, so its copy button is disabled. Create a new key, or choose Rotate from its row menu, to get one you can copy again; after a rotation the old key keeps working for up to 24 hours while you switch.
3

Set a spending limit or an expiration under Limits, or accept the defaults

A key follows your workspace’s current rate allocation, including later upgrades. A key that already carries a custom per-key rate limit keeps it, clamped to the workspace maximum.A monthly spending limit is off unless you turn it on. When set, pay-as-you-go requests on that key are refused with 402 spend_limit_reached once the key’s settled spend in the current calendar month (UTC) reaches the limit, and the month resets on the first. It is per key, so the workspace’s other keys and its credits are unaffected, and you can set, raise, or remove it later with Set limit in the key’s row menu under Settings, API keys. Minimum $1.00.New keys have no scheduled expiry by default, but rotating a key gives the previous key a limited grace period. When you do turn expiration on the form starts at 90 days, and you can choose 30, 60, 90 days or 1 year.

Coding plan and Credits only

Your plan covers chat (chat completions, messages and responses) from every workspace key except keys marked Credits only, and embeddings and rerank whenever those models are available. An owner can set Credits only at Settings > API keys. The setting is off by default and survives rotation. It bypasses the coding plan, Standby, and the credits cap after plan limits. Normal wallet and key controls still apply. On a serving coding plan, a per-key spending limit blocks credits after plan limits. It does not stop requests paid by the plan or eligible Standby usage. Use Credits only when a key must always follow pay-as-you-go credit controls. See Coding plan.

Send it

Key format

Every key is rp_ followed by 40 lowercase letters or digits.
At rest a key is a versioned HMAC-SHA-256 digest, which is what authenticates your requests, plus an AES-256-GCM encrypted copy bound to that key, which is what lets you copy it again. Both depend on a secret held outside the database, so a copy of the database alone cannot reveal a usable key. Revoking a key erases its encrypted copy. If Settings marks a key as an older format, rotate it from that row and the replacement uses the current one.

Workspace keys

Use a workspace-scoped key with https://api.runinfra.ai/v1 and select a hosted model with the model field. A legacy key limited to part of the workspace returns 400 auth_error on the flat /v1 base URL. Replace it with a workspace key for Model APIs.

Rotate, revoke, expire

Key lifecycleno downtime to replace a keycreatecopy it again any timerotatea new secret is issuedboth validdeploy and drain trafficrevoke old403 on the old keyexpirationruns on its own clock. After the expiry you set, the key answers 401.We keep a one-way digest to check requests and an encrypted copy you can copy while the key is live.
Key lifecycleno downtime to replace a keycreatecopy it again any timerotatea new secret is issuedboth validdeploy and drain trafficrevoke old403 on the old keyexpirationruns on its own clock. After the expiry you set, the key answers 401.We keep a one-way digest to check requests and an encrypted copy you can copy while the key is live.
By default, rotation keeps the previous key active for up to 24 hours, or until its existing expiry if that comes first. Revoking it ends the grace period immediately. During a rate-limit store outage, a revoked key can keep working for up to about 30 seconds. A successful rotation revokes live predecessors found in its retained rotation history in the same operation. Older keys outside that history can remain live and count toward the scope ceiling. Rotation cannot leave more than 20 live customer API keys in a scope, twice the normal cap of 10. A rotation that would exceed this ceiling returns HTTP 400 with top-level code api_key_rotation_overlap_limit, without changing existing keys. Revoke an unneeded live key in that scope, then retry. While another key operation for the same scope is still in progress, creating or rotating a key can answer HTTP 503 with top-level code api_key_mint_busy and a Retry-After: 2 header; nothing changed, wait two seconds and send the same request again. For a rotation without downtime, choose Rotate from the key’s row menu and leave Revoke previous key immediately clear, deploy the new secret, let traffic drain, then choose Revoke from the previous key’s row menu. Select Revoke previous key immediately when you need the previous key revoked as part of rotation. A revoked key remains deactivated after archival and is refused with 403 and the message API key is deactivated. An unknown or permanently deleted key returns 401 with Invalid API key. Branch on error.type and error.code, never on the message text. Expiration is checked on every request, so there is no window in which an expired key still works. An expired key returns 401.

Environment variables

RUNINFRA_API_KEY is the name the CLI and most coding-agent integrations read. Mistral Vibe, Oh My Pi and Goose read their own variable instead, such as RUNINFRA_GOOSE_API_KEY, and so does Crush set up with --key-source env; setup writes it for you. RUNINFRA_API_KEY is not an automatic alias for RUNINFRA_GATEWAY_KEY. Set both to the same key if you use both paths. The assignment above sets both explicitly. Most OpenAI clients pick up OPENAI_API_KEY on their own, so map OPENAI_API_KEY=$RUNINFRA_GATEWAY_KEY and OPENAI_BASE_URL=$RUNINFRA_BASE_URL. Anthropic clients use the bare host because they append /v1. ANTHROPIC_AUTH_TOKEN sends Bearer auth. ANTHROPIC_API_KEY also works through x-api-key on the Messages routes and GET /v1/models. Use a separate key per environment so one leak has a bounded blast radius. RightNow Agent reads RIGHTNOW_API_KEY first, then RUNINFRA_GATEWAY_KEY. A nonempty environment credential overrides its stored key.

Security posture

Hashed and encrypted at rest

A versioned HMAC-SHA-256 digest authenticates requests, and an AES-256-GCM copy bound to its key lets you copy it again. The plaintext is never stored unencrypted.

Constant-time compare

Lookup is by indexed hash, not string comparison, so timing cannot enumerate keys.

Audit log

Key lifecycle changes, every copy of a key, and attributable authentication failures are logged for SOC2 CC6.6.

Per-key rate limit

A sliding 60 second window per key, or a fixed 60 second window on each server during a rate-limit store outage. If the rate-limit store is not configured, the request is refused with 503 limiter_unavailable rather than admitted, and nothing is charged.

Per-key spending limit

An optional monthly budget on one key, enforced on settled spend and reset on the first of the month (UTC). The refusal is 402 spend_limit_reached with the limit, the spend, and the reset instant.

Model APIs quickstart

Make your first call with the key you just created.

Chat completions

The full request contract.

Rate limits

What the per-key limit you set actually governs.