Skip to main content

Authentication

Every request needs a Standard Compute API key. Create and manage keys in the dashboard.

Sending your key​

Send the key as a bearer token:

Authorization: Bearer YOUR_API_KEY

The Messages API also accepts the Anthropic-style header, so Anthropic SDKs work unchanged:

x-api-key: YOUR_API_KEY

If both headers are present, Authorization is used.

Keeping keys safe​

  • Store keys in environment variables or your tool's secret store, not in source code.
  • Never send a key in a URL query parameter.
  • If a key leaks, rotate it in the dashboard to revoke the old one.

Company keys​

On a team plan, company admins create keys for members. Company keys use the company's budget. With the launcher, add --choose-key to pick between your personal and company keys.

Errors​

A missing or invalid key returns 401. A company key that has been disabled returns 403. See Errors.