Skip to main content
Every public inference request requires an Aixy API key in the HTTP Authorization header:
The key identifies both the caller and its project. This allows the gateway to apply the same model policies, guardrails, routing rules, budgets, and usage attribution whether traffic originates in Playground or an external application.

Create and manage a key

Open API keys from the account menu and select Create API key. Enter a recognizable name, select the project, optionally record the workload and team cost center, and choose a lifetime. Copy the issued secret directly into your application’s secret store. From the key’s lifecycle actions, use Rotate to issue a new secret under the same logical key, Disable for a reversible pause, or Revoke to permanently retire it. Re-enable a disabled key only while its original expiration remains valid. See the quickstart for a complete first-request walkthrough.

Key handling

  • Create separate keys for separate applications and environments.
  • Record the workload owner and choose a finite TTL whenever the deployment lifecycle permits it.
  • Store secrets in a managed secret store or protected server-side environment variable.
  • Rotate keys with the shortest overlap your deployment needs. Only the immediate predecessor can remain valid during an overlap, for at most 24 hours.
  • Disable a key for reversible incident containment; revoke it when it must never be restored.
  • Revoke a key immediately when it may have been exposed.
  • Never log the complete key or include it in URLs, query strings, client-side code, screenshots, support messages, or source control.
  • Use the visible suffix in the dashboard to identify a key without revealing it.
Creation and rotation return a raw secret exactly once. Aixy retains only its SHA-256 hash and non-secret version metadata. A logical key keeps the same identifier across rotations, while its absolute expiration caps both the current version and any overlap. Lifecycle mutations are written to the tenant audit log without recording the secret or hash.

Request correlation

Every inference response includes an x-request-id header. Copy its value into the Activity page when you need to inspect that individual request. Aixy returns the header for successful, streamed, and gateway-error responses. If you do not provide an identifier, Aixy generates one. You may instead send your own opaque identifier to correlate the request with your application logs:
Aixy returns the same identifier in the response header and preserves it for operational debugging. Do not put personal data, secrets, or business payloads in the identifier.
Provider credentials are different from Aixy API keys. Provider credentials are encrypted control-plane configuration; applications should normally send only the project-scoped Aixy key.

Last use

Trusted external usage monitors can also use a gateway key to read its own consumption and applicable budget balances. See External usage monitors. This does not make the key read-only or grant browser-session access to administration APIs. The API keys page shows when each key was last used for an authenticated model request, model catalog lookup, or Playground request. Provider failures still count as use. The timestamp belongs to the logical key and stays available when its secret rotates. Updates normally appear within 30 seconds, after refreshing the page. No recorded use means Aixy has not recorded a use, including for existing keys whose earlier history is unavailable. Recording is best effort: interrupted instances, database outages, or heavy load can delay or lose recent observations. This timestamp is an activity indicator, not an audit trail.