TokenLab

Getting Started

Authentication

Authenticate TokenLab API requests with an API key

API Keys

Model calls and private resources require an API key. Public discovery endpoints such as GET /v1/models and GET /v1/models/{model} work without one. A successful discovery response does not verify that your key works; follow the Quickstart to send a model request. Use the complete saved key; the prefix in the key list cannot authenticate.

For OpenAI-compatible endpoints, send it as:

Authorization: Bearer sk-your-api-key

For Anthropic-compatible /v1/messages requests, you can also use:

x-api-key: sk-your-api-key

Management Tokens

Management API endpoints use a separate token type:

Authorization: Bearer mt-your-management-token

Use management tokens only with /v1/management/* endpoints. Open API → Tokens for the selected workspace to create or replace a token. Save the full token when it is shown; it is displayed only once after creation or replacement.

Management tokens cannot be used for model inference, and standard sk-... API keys cannot be used for the Management API.

Get an API key

  1. Sign in to TokenLab Console
  2. Open API Keys
  3. Create a new key
  4. Give it a descriptive name
  5. Copy it immediately because it is shown only once
  • Never expose API keys in client-side code
  • Never commit API keys to version control
  • Use environment variables or a secret manager
  • Rotate keys periodically
  • Delete unused keys

Use an API key

See the Quickstart for environment variables and a complete first request. Use the SDK matching your chosen API format; keep keys on the server.

Set a usage limit

You can set a usage limit on each API key:

SettingDescription
No LimitKey uses your account balance without restrictions
Fixed LimitKey stops working after reaching the specified amount

Key prefix

All TokenLab API keys start with sk-.

Error Responses

Status CodeTypeCodeDescription
401invalid_api_keyinvalid_api_keyThe API key is missing, invalid, inactive, or revoked
401expired_api_keyexpired_api_keyThe key has expired
402insufficient_balanceinsufficient_balanceAccount balance is insufficient
402quota_exceededquota_exceededAPI key usage limit reached

Example:

{
  "error": {
    "message": "Invalid API key provided",
    "type": "invalid_api_key",
    "code": "invalid_api_key"
  }
}

On this page