GET STARTED
API keys & authentication
Connect securely with a key from your Tokely dashboard.
Authenticate a request
Include your key in the Authorization header on every request, including GET /v1/models. Your website login session does not authenticate inference requests.
Authorization: Bearer <YOUR_TOKELY_API_KEY>Manage your keys
Create and revoke keys in Dashboard → API keys. Copy a newly created secret when it is shown. If a key is exposed, revoke it and replace it in your application.
Invalid, expired or revoked keys return HTTP 401. HTTP 403 means the key or account does not have permission to make the request.
Keep the secret on your server
Load keys from environment variables or a secret manager. Route browser and mobile requests through your backend. Do not put keys in public JavaScript, repositories or URLs.
Use the Tokely key as issued. Provider keys and model routing suffixes are not accepted.