Authentication

Authentication

Pass your key as a bearer token. The x-api-key header is also accepted for clients that prefer it.

http
Authorization: Bearer ar-xxxxxxxxxxxx

# or
x-api-key: ar-xxxxxxxxxxxx

Key properties

PropertyMeaning
prefixEvery key starts with ar- so it is easy to spot in logs and secret scanners.
rate_limitRequests per minute for this key. 0 means no per-key limit.
allowed_modelsOptional allowlist. When set, the key may only call those model ids; anything else returns 403.
enabledRevoking flips this to false. The key stops working immediately, with no grace window.

Good practice

Create one key per application rather than sharing a single key. Usage is logged per key, so separate keys give you a per-app cost breakdown and let you revoke one without disrupting the others. Never commit a key to source control or ship it in client-side code. Anyone holding it can spend your balance.

A key is shown in full exactly once, at creation. If you lose it, revoke it and create a new one; we cannot recover the original value.