Authorization: Bearer header on every endpoint. The Anthropic-compatible routes, /v1/messages and /v1/messages/count_tokens, also accept x-api-key. So do GET /v1/models and GET /v1/models/{model}. A non-blank x-api-key wins when both headers are present on those routes.
Get a key
1
Open the model page, or Settings
Select Get API key on a page in the Model Library, or select Create API key in Settings > API keys. Both paths give you a workspace key for hosted Model APIs.
2
Copy the key
Copy it from the dialog. You can copy it again whenever you need it with the copy button on its row in Settings > API keys. The member who created a key and the workspace owner can copy it, other members and viewers cannot, and every copy is recorded in the audit log.Keys made before copying existed show a disabled copy button. Create a new key, or Rotate this one, to get a copyable key; after a rotation the old key keeps working for up to 24 hours.
3
Set a spending limit or an expiration under Limits, or accept the defaults
A key follows your workspace’s current rate allocation, including later upgrades. A key that already carries a custom per-key rate limit keeps it, clamped to the workspace maximum.A monthly spending limit is off until you set one (minimum $1.00). Once the key’s settled spend in the UTC month (it resets on the 1st) reaches it, pay-as-you-go requests on that key get
402 spend_limit_reached with the limit, the spend and the reset time. Other keys and the credit balance are unaffected; change it with Set limit in the key’s row menu.New keys have no scheduled expiry by default, but rotating a key gives the previous key a limited grace period. When you do turn expiration on the form starts at 90 days, and you can choose 30, 60, 90 days or 1 year.Coding plan and Credits only
Your plan covers chat (chat completions, messages and responses) from every workspace key except keys marked Credits only, and embeddings and rerank whenever those models are available. An owner can set Credits only at Settings > API keys. The setting is off by default and survives rotation. It bypasses the coding plan, Standby, and the credits cap after plan limits. Normal wallet and key controls still apply. On a serving coding plan, a per-key spending limit blocks credits after plan limits. It does not stop requests paid by the plan or eligible Standby usage. Use Credits only when a key must always follow pay-as-you-go credit controls. See Coding plan.Send it
Key format
Every key isrp_ followed by 40 lowercase letters or digits.
Workspace keys
Use a workspace-scoped key withhttps://api.runinfra.ai/v1 and select a hosted model with the model field.
A legacy key scoped to one deployment returns 400 auth_error here. Replace it with a workspace key.
Rotate, revoke, expire
Rotation keeps the previous key working for up to 24 hours by default, or until its own expiry if that comes sooner, and Revoke ends that grace period. For no downtime, choose Rotate from the key’s row menu with Revoke previous key immediately clear, deploy the new key, let traffic drain, then choose Revoke on the previous key. Check Revoke previous key immediately when the previous key must stop at once.
Branch on codes, never on message text: the
401 and 403 carry error.type and error.code, the 400 and 503 key operations a top-level code. During a rate-limit store outage, a revoked key can keep working for up to about 30 seconds. A rotation also revokes the earlier keys in its own rotation history that are still live; other older keys stay live and count toward the 20. Expiration is checked on every request, so an expired key stops working the moment it expires.
Environment variables
RUNINFRA_API_KEY is the name the RunInfra CLI and most coding-agent integrations read. Mistral Vibe, Oh My Pi and Goose read their own variable instead, such as RUNINFRA_GOOSE_API_KEY, and so does Crush set up with --key-source env; setup writes it for you. It is not an alias for RUNINFRA_GATEWAY_KEY, so set both, as the block above does.
Most OpenAI clients pick up OPENAI_API_KEY on their own, so the block above maps it, with OPENAI_BASE_URL, to RunInfra. Anthropic clients use the bare host because they append /v1. ANTHROPIC_AUTH_TOKEN sends Bearer auth. ANTHROPIC_API_KEY also works through x-api-key on the Messages routes and GET /v1/models. Use a separate key per environment so one leak has a bounded blast radius.
RightNow Agent reads RIGHTNOW_API_KEY first, then RUNINFRA_GATEWAY_KEY. A nonempty environment credential overrides its stored key.
Security posture
Hashed and encrypted at rest
A versioned HMAC-SHA-256 digest authenticates requests, and an AES-256-GCM copy bound to its key lets you copy it again. The plaintext is never stored unencrypted.
Constant-time compare
Lookup is by indexed hash and the match is constant-time, so timing cannot enumerate keys.
Audit log
Key lifecycle changes, every copy of a key, and attributable authentication failures are logged for SOC 2 CC6.6.
Per-key rate limit
A sliding 60 second window per key, or a fixed 60 second window on each server during a rate-limit store outage. If the rate-limit store is not configured, the request is refused with
503 limiter_unavailable rather than admitted, and nothing is charged.Per-key spending limit
An optional monthly budget on one key, enforced on settled spend and reset on the first of the month (UTC). The refusal is
402 spend_limit_reached with the limit, the spend, and the reset instant.Related
Model APIs quickstart
Make your first call with the key you just created.
Chat completions
The full request contract.
Rate limits
What the per-key limit you set actually governs.