Skip to main content
Use a workspace API key in an Authorization: Bearer header on every endpoint. The Anthropic-compatible routes, /v1/messages and /v1/messages/count_tokens, also accept x-api-key. So do GET /v1/models and GET /v1/models/{model}. A non-blank x-api-key wins when both headers are present on those routes.

Get a key

1

Open the model page, or Settings

Select Get API key on a page in the Model Library, or select Create API key in Settings > API keys. Both paths give you a workspace key for hosted Model APIs.
2

Copy the key

Copy it from the dialog. You can copy it again whenever you need it with the copy button on its row in Settings > API keys. The member who created a key and the workspace owner can copy it, other members and viewers cannot, and every copy is recorded in the audit log.Keys made before copying existed show a disabled copy button. Create a new key, or Rotate this one, to get a copyable key; after a rotation the old key keeps working for up to 24 hours.
3

Set a spending limit or an expiration under Limits, or accept the defaults

A key follows your workspace’s current rate allocation, including later upgrades. A key that already carries a custom per-key rate limit keeps it, clamped to the workspace maximum.A monthly spending limit is off until you set one (minimum $1.00). Once the key’s settled spend in the UTC month (it resets on the 1st) reaches it, pay-as-you-go requests on that key get 402 spend_limit_reached with the limit, the spend and the reset time. Other keys and the credit balance are unaffected; change it with Set limit in the key’s row menu.New keys have no scheduled expiry by default, but rotating a key gives the previous key a limited grace period. When you do turn expiration on the form starts at 90 days, and you can choose 30, 60, 90 days or 1 year.

Coding plan and Credits only

Your plan covers chat (chat completions, messages and responses) from every workspace key except keys marked Credits only, and embeddings and rerank whenever those models are available. An owner can set Credits only at Settings > API keys. The setting is off by default and survives rotation. It bypasses the coding plan, Standby, and the credits cap after plan limits. Normal wallet and key controls still apply. On a serving coding plan, a per-key spending limit blocks credits after plan limits. It does not stop requests paid by the plan or eligible Standby usage. Use Credits only when a key must always follow pay-as-you-go credit controls. See Coding plan.

Send it

Key format

Every key is rp_ followed by 40 lowercase letters or digits.
The stored digest and encrypted copy both depend on a secret held outside the database, so a copy of the database alone cannot reveal a usable key. Revoking a key erases its encrypted copy. If Settings marks a key as an older format, rotate it from that row and the replacement uses the current one.

Workspace keys

Use a workspace-scoped key with https://api.runinfra.ai/v1 and select a hosted model with the model field. A legacy key scoped to one deployment returns 400 auth_error here. Replace it with a workspace key.

Rotate, revoke, expire

Key lifecycleno downtime to replace a keycreatecopy it again any timerotatea new secret is issuedboth validdeploy and drain trafficrevoke old403 on the old keyexpirationruns on its own clock. After the expiry you set, the key answers 401.
Key lifecycleno downtime to replace a keycreatecopy it again any timerotatea new secret is issuedboth validdeploy and drain trafficrevoke old403 on the old keyexpirationruns on its own clock. After the expiry you set, the key answers 401.
Rotation keeps the previous key working for up to 24 hours by default, or until its own expiry if that comes sooner, and Revoke ends that grace period. For no downtime, choose Rotate from the key’s row menu with Revoke previous key immediately clear, deploy the new key, let traffic drain, then choose Revoke on the previous key. Check Revoke previous key immediately when the previous key must stop at once. Branch on codes, never on message text: the 401 and 403 carry error.type and error.code, the 400 and 503 key operations a top-level code. During a rate-limit store outage, a revoked key can keep working for up to about 30 seconds. A rotation also revokes the earlier keys in its own rotation history that are still live; other older keys stay live and count toward the 20. Expiration is checked on every request, so an expired key stops working the moment it expires.

Environment variables

RUNINFRA_API_KEY is the name the RunInfra CLI and most coding-agent integrations read. Mistral Vibe, Oh My Pi and Goose read their own variable instead, such as RUNINFRA_GOOSE_API_KEY, and so does Crush set up with --key-source env; setup writes it for you. It is not an alias for RUNINFRA_GATEWAY_KEY, so set both, as the block above does. Most OpenAI clients pick up OPENAI_API_KEY on their own, so the block above maps it, with OPENAI_BASE_URL, to RunInfra. Anthropic clients use the bare host because they append /v1. ANTHROPIC_AUTH_TOKEN sends Bearer auth. ANTHROPIC_API_KEY also works through x-api-key on the Messages routes and GET /v1/models. Use a separate key per environment so one leak has a bounded blast radius. RightNow Agent reads RIGHTNOW_API_KEY first, then RUNINFRA_GATEWAY_KEY. A nonempty environment credential overrides its stored key.

Security posture

Hashed and encrypted at rest

A versioned HMAC-SHA-256 digest authenticates requests, and an AES-256-GCM copy bound to its key lets you copy it again. The plaintext is never stored unencrypted.

Constant-time compare

Lookup is by indexed hash and the match is constant-time, so timing cannot enumerate keys.

Audit log

Key lifecycle changes, every copy of a key, and attributable authentication failures are logged for SOC 2 CC6.6.

Per-key rate limit

A sliding 60 second window per key, or a fixed 60 second window on each server during a rate-limit store outage. If the rate-limit store is not configured, the request is refused with 503 limiter_unavailable rather than admitted, and nothing is charged.

Per-key spending limit

An optional monthly budget on one key, enforced on settled spend and reset on the first of the month (UTC). The refusal is 402 spend_limit_reached with the limit, the spend, and the reset instant.

Model APIs quickstart

Make your first call with the key you just created.

Chat completions

The full request contract.

Rate limits

What the per-key limit you set actually governs.