Creating a Management API Key
To use the key management API, you first need to create a Management API key:- Go to the Management API Keys page
- Click “Create New Key”
- Enter a name and choose an expiration
- Copy the key when it is shown. You will not be able to see it again
Expiration
We recommend setting an expiration date on every management key. A leaked management key could create, edit and delete the API keys in your account other than those provisioned by a Connect client, and one with no expiration stays valid until you delete it.- The expiration is fixed when the key is created and cannot be changed afterwards. To extend access, create a new key and delete the old one.
- Once a key’s expiration passes, every request that uses it fails with
401 Unauthorizedand the messageAPI key expired. Expired keys still appear on the Management API Keys page until you delete them.
Use Cases
Common scenarios for programmatic key management include:- SaaS Applications: Automatically create unique API keys for each customer instance
- Key Rotation: Regularly rotate API keys for security compliance
- Usage Monitoring: Track key usage and automatically disable keys that exceed limits (with optional daily/weekly/monthly limit resets)
Example Usage
All key management endpoints are under/api/v1/keys and require a Management API key in the Authorization header.
Response Format
API responses return JSON objects containing key information:Organization Settings
A management key created in an organization can also read and update that organization’s settings at/api/v1/organization/settings. The organization is the one the key belongs to; it cannot be chosen per request.
Currently exposed setting:
is_filtered_model_catalog_enabled(defaultfalse): the same switch as Settings → Privacy → “Filter the model catalog for API keys”. When enabled,GET /api/v1/modelscalled with one of the organization’s API keys returns only the models that key can use (the/api/v1/models/usercatalog), and the signed-in dashboard shows the same list. Requests without a key still receive the public catalog. Which models remain visible is decided by the active workspace’s guardrails and provider preferences; enabling the switch does not change those.
cURL
404 Not Found from these routes.