Authentication
Authentication
Pass your key as a bearer token. The x-api-key header is also accepted for clients that prefer it.
http
Authorization: Bearer ar-xxxxxxxxxxxx # or x-api-key: ar-xxxxxxxxxxxx
Key properties
| Property | Meaning |
|---|---|
| prefix | Every key starts with ar- so it is easy to spot in logs and secret scanners. |
| rate_limit | Requests per minute for this key. 0 means no per-key limit. |
| allowed_models | Optional allowlist. When set, the key may only call those model ids; anything else returns 403. |
| enabled | Revoking flips this to false. The key stops working immediately, with no grace window. |
Good practice
Create one key per application rather than sharing a single key. Usage is logged per key, so separate keys give you a per-app cost breakdown and let you revoke one without disrupting the others. Never commit a key to source control or ship it in client-side code. Anyone holding it can spend your balance.
A key is shown in full exactly once, at creation. If you lose it, revoke it and create a new one; we cannot recover the original value.