Docs/API keys

GET STARTED

API keys & authentication

Connect securely with a key from your Tokely dashboard.

Manage your keys

Create and revoke keys in Dashboard → API keys. Copy a newly created secret when it is shown. If a key is exposed, revoke it and replace it in your application.

Invalid, expired or revoked keys return HTTP 401. HTTP 403 means the key or account does not have permission to make the request.

Keep the secret on your server

Load keys from environment variables or a secret manager. Route browser and mobile requests through your backend. Do not put keys in public JavaScript, repositories or URLs.

Use the Tokely key as issued. Provider keys and model routing suffixes are not accepted.

Get your API key Browse models