Getting Started
Authentication
Authenticate TokenLab API requests with an API key
API Keys
Model calls and private resources require an API key. Public discovery endpoints such as GET /v1/models and GET /v1/models/{model} work without one. A successful discovery response does not verify that your key works; follow the Quickstart to send a model request. Use the complete saved key; the prefix in the key list cannot authenticate.
For OpenAI-compatible endpoints, send it as:
Authorization: Bearer sk-your-api-keyFor Anthropic-compatible /v1/messages requests, you can also use:
x-api-key: sk-your-api-keyManagement Tokens
Management API endpoints use a separate token type:
Authorization: Bearer mt-your-management-tokenUse management tokens only with /v1/management/* endpoints. Open API → Tokens for the selected workspace to create or replace a token. Save the full token when it is shown; it is displayed only once after creation or replacement.
Management tokens cannot be used for model inference, and standard sk-... API keys cannot be used for the Management API.
Get an API key
- Sign in to TokenLab Console
- Open API Keys
- Create a new key
- Give it a descriptive name
- Copy it immediately because it is shown only once
- Never expose API keys in client-side code
- Never commit API keys to version control
- Use environment variables or a secret manager
- Rotate keys periodically
- Delete unused keys
Use an API key
See the Quickstart for environment variables and a complete first request. Use the SDK matching your chosen API format; keep keys on the server.
Set a usage limit
You can set a usage limit on each API key:
| Setting | Description |
|---|---|
| No Limit | Key uses your account balance without restrictions |
| Fixed Limit | Key stops working after reaching the specified amount |
Key prefix
All TokenLab API keys start with sk-.
Error Responses
| Status Code | Type | Code | Description |
|---|---|---|---|
| 401 | invalid_api_key | invalid_api_key | The API key is missing, invalid, inactive, or revoked |
| 401 | expired_api_key | expired_api_key | The key has expired |
| 402 | insufficient_balance | insufficient_balance | Account balance is insufficient |
| 402 | quota_exceeded | quota_exceeded | API key usage limit reached |
Example:
{
"error": {
"message": "Invalid API key provided",
"type": "invalid_api_key",
"code": "invalid_api_key"
}
}