Authentication & API keys
Authenticate with a bearer token and manage per-key spend limits and model allowlists in the Dashboard.
Authentication & API keys
Every request must carry an Authorization header with a bearer token:
Authorization: Bearer sk-inf-xxxxxxxxxxxxxxxxxxxxxxxx
Keys always begin with sk-inf-. A missing header returns 401 unauthorized; an unknown or malformed key returns 401 invalid_api_key; a disabled key returns 403 api_key_disabled.
Managing keys
From API Keys in the Dashboard you can:
| Action | Description |
|---|---|
| Create a key | The full key is displayed once. Afterwards only the prefix and last four characters are shown. |
| Disable / enable | Disabling takes effect immediately; subsequent requests return api_key_disabled. |
| Delete a key | Permanent and irreversible. |
| Monthly spend limit | Denominated in USD. Once the month's accumulated cost reaches the limit, requests return spend_limit_reached. Resets at the start of the next month. |
| Model allowlist | Restricts which models this key may call. Anything outside the list returns model_not_allowed. |
| Usage view | Requests, tokens and cost per key. |
We recommend one key per purpose (for example production, staging, local-dev) so limits can be tuned independently and a single key can be revoked without affecting the rest.
Usage examples
curl
curl https://api.alphacurve.io/v1/models \
-H "Authorization: Bearer $INFERENCE_API_KEY"
Python
import os
from openai import OpenAI
client = OpenAI(
base_url="https://api.alphacurve.io/v1",
api_key=os.environ["INFERENCE_API_KEY"],
)
print([m.id for m in client.models.list().data])
Node / TypeScript
import OpenAI from "openai";
const client = new OpenAI({
baseURL: "https://api.alphacurve.io/v1",
apiKey: process.env.INFERENCE_API_KEY!,
});
const models = await client.models.list();
console.log(models.data.map((m) => m.id));
Checking whether a key works
The cheapest health check is GET /v1/models — it consumes no tokens:
curl -i https://api.alphacurve.io/v1/models \
-H "Authorization: Bearer sk-inf-does-not-exist"
HTTP/1.1 401 Unauthorized
Content-Type: application/json
{
"error": {
"code": "invalid_api_key",
"message": "The provided API key is invalid."
}
}
Security guidance
- Keep keys server-side. Never ship them in a browser, a mobile app, or any frontend bundle — that is equivalent to publishing them. If your frontend needs an LLM, proxy through your own backend.
- Never commit keys. Use environment variables or a secrets manager, and add
.envto.gitignore. - Always set a spend limit on keys that leave your machine. It is your last line of defence if a key leaks.
- Rotate regularly. Create the new key, deploy, confirm traffic has moved, then disable the old one — zero-downtime rotation.
- Disable immediately on leak. Disabling takes effect right away.