Authorization header:
Create and manage a key
Open API keys from the account menu and select Create API key. Enter a recognizable name, select the project, optionally record the workload and team cost center, and choose a lifetime. Copy the issued secret directly into your application’s secret store. From the key’s lifecycle actions, use Rotate to issue a new secret under the same logical key, Disable for a reversible pause, or Revoke to permanently retire it. Re-enable a disabled key only while its original expiration remains valid. See the quickstart for a complete first-request walkthrough.Key handling
- Create separate keys for separate applications and environments.
- Record the workload owner and choose a finite TTL whenever the deployment lifecycle permits it.
- Store secrets in a managed secret store or protected server-side environment variable.
- Rotate keys with the shortest overlap your deployment needs. Only the immediate predecessor can remain valid during an overlap, for at most 24 hours.
- Disable a key for reversible incident containment; revoke it when it must never be restored.
- Revoke a key immediately when it may have been exposed.
- Never log the complete key or include it in URLs, query strings, client-side code, screenshots, support messages, or source control.
- Use the visible suffix in the dashboard to identify a key without revealing it.
Request correlation
Every inference response includes anx-request-id header. Copy its value into the Activity page
when you need to inspect that individual request. Aixy returns the header for successful, streamed,
and gateway-error responses.
If you do not provide an identifier, Aixy generates one. You may instead send your own opaque
identifier to correlate the request with your application logs:
Provider credentials are different from Aixy API keys. Provider credentials are encrypted
control-plane configuration; applications should normally send only the project-scoped Aixy key.