Skip to content

Authentication & API keys

Authenticate with a bearer token and manage per-key spend limits and model allowlists in the Dashboard.

Authentication & API keys

Every request must carry an Authorization header with a bearer token:

Authorization: Bearer sk-inf-xxxxxxxxxxxxxxxxxxxxxxxx

Keys always begin with sk-inf-. A missing header returns 401 unauthorized; an unknown or malformed key returns 401 invalid_api_key; a disabled key returns 403 api_key_disabled.

Managing keys

From API Keys in the Dashboard you can:

ActionDescription
Create a keyThe full key is displayed once. Afterwards only the prefix and last four characters are shown.
Disable / enableDisabling takes effect immediately; subsequent requests return api_key_disabled.
Delete a keyPermanent and irreversible.
Monthly spend limitDenominated in USD. Once the month's accumulated cost reaches the limit, requests return spend_limit_reached. Resets at the start of the next month.
Model allowlistRestricts which models this key may call. Anything outside the list returns model_not_allowed.
Usage viewRequests, tokens and cost per key.

We recommend one key per purpose (for example production, staging, local-dev) so limits can be tuned independently and a single key can be revoked without affecting the rest.

Usage examples

curl

curl https://api.alphacurve.io/v1/models \
  -H "Authorization: Bearer $INFERENCE_API_KEY"

Python

import os
from openai import OpenAI

client = OpenAI(
    base_url="https://api.alphacurve.io/v1",
    api_key=os.environ["INFERENCE_API_KEY"],
)

print([m.id for m in client.models.list().data])

Node / TypeScript

import OpenAI from "openai";

const client = new OpenAI({
  baseURL: "https://api.alphacurve.io/v1",
  apiKey: process.env.INFERENCE_API_KEY!,
});

const models = await client.models.list();
console.log(models.data.map((m) => m.id));

Checking whether a key works

The cheapest health check is GET /v1/models — it consumes no tokens:

curl -i https://api.alphacurve.io/v1/models \
  -H "Authorization: Bearer sk-inf-does-not-exist"
HTTP/1.1 401 Unauthorized
Content-Type: application/json

{
  "error": {
    "code": "invalid_api_key",
    "message": "The provided API key is invalid."
  }
}

Security guidance

  • Keep keys server-side. Never ship them in a browser, a mobile app, or any frontend bundle — that is equivalent to publishing them. If your frontend needs an LLM, proxy through your own backend.
  • Never commit keys. Use environment variables or a secrets manager, and add .env to .gitignore.
  • Always set a spend limit on keys that leave your machine. It is your last line of defence if a key leaks.
  • Rotate regularly. Create the new key, deploy, confirm traffic has moved, then disable the old one — zero-downtime rotation.
  • Disable immediately on leak. Disabling takes effect right away.