Skip to main content

Identity and Access

AI Gateway identifies callers through API keys. Create recognizable keys for applications to manage expiry, spending, and cost attribution separately.

Choose the correct identity and credential​

CredentialPurpose
Personal API keyGateway requests billed to the personal account
Organization API keyGateway requests billed to the organization
Git Access TokenGit and platform API access; not a substitute for a gateway key
Upstream provider credentialUsed by administrators to configure providers; not the application's gateway credential

See Custom User Systems and Organizations for enterprise login and membership. After signing in, use a personal or organization API key with access to the target service.

Create and maintain an API key​

  1. Open Account Settings → API Keys for a personal key or Organization Settings → API Keys for an organization key.
  2. Give the key a recognizable name, such as production-support or evaluation-test.
  3. Set a spending allowance and expiration appropriate to the application.
  4. Save the generated key. Its full value is shown only once.
  5. Configure it in the application runtime and make a request to check identity and attribution.

For routine replacement, switch applications to the new key before deleting the old one. Revoke exposed credentials immediately. Deleted keys no longer authorize requests. See API Keys for complete screen instructions.

Check model access​

Service status, resource visibility, and caller identity affect access. Follow each dedicated endpoint's API instructions for the appropriate identity. Permission to view or edit an endpoint page is distinct from permission to invoke inference.

Check all of the following:

  • The service is enabled and its upstream is available.
  • The key belongs to the intended person or organization and is valid.
  • The caller has access to the service and the key has remaining spending allowance.

Model and organization controls depend on the installed version. Create separate application keys to manage their spending allowances and expiration dates individually.

Limits, Metering, and Costs · Content Safety and Data Handling · Team Management and Operations