API Keys Management
Overview
API keys are the primary authentication method for Tokenlio API. Each key provides programmatic access to your workspace resources and usage balance.
Creating API Keys
From Console
- Log in to api.tokenlio.ai
- Navigate to API Keys in the sidebar
- Click "Create API Key"
- Enter a descriptive name (e.g., "Production Server", "Development")
- Click "Create"
The key will be displayed once. Copy and store it securely.
Key Format
tk-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx- Prefix:
tk- - Length: 43 characters
- Character set: alphanumeric
Managing API Keys
Viewing Keys
The console shows:
- Key name
- Prefix (first 8 characters)
- Creation date
- Last used timestamp
- Usage statistics
Revoking Keys
To revoke a key:
- Navigate to API Keys
- Click the Delete icon next to the key
- Confirm revocation
Note: Revoked keys stop working immediately. All requests using revoked keys will return 401 Unauthorized.
Security Best Practices
Storage
- ✅ Store keys in environment variables
- ✅ Use secret management services (AWS Secrets Manager, HashiCorp Vault)
- ✅ Restrict file permissions (0600)
- ❌ Never commit keys to version control
- ❌ Never share keys in chat/email
- ❌ Never embed keys in client-side code
Rotation
Rotate API keys regularly:
- Create a new key
- Update your applications
- Verify the new key works
- Revoke the old key
Recommended rotation interval: 90 days
Monitoring
Monitor key usage:
- Check "Last Used" timestamp
- Review usage patterns
- Set up alerts for unusual activity
Organization Keys
For team workspaces:
- Create separate keys for each service/environment
- Use descriptive names
- Document key purposes
- Audit key usage regularly
Key Permissions
All keys in a workspace have the same permissions:
- Make API requests to all models
- View usage and billing
- Cannot create/delete keys
- Cannot modify workspace settings
- Cannot manage members
Rate Limits
Rate limits are per-workspace, not per-key:
- Default: 100 requests/minute
- Enterprise: Custom limits available
Contact support@tokenlio.ai for higher limits.
Troubleshooting
401 Unauthorized
Cause: Invalid or revoked key
Solution:
- Verify key format (starts with
tk-) - Check key hasn't been revoked
- Ensure you're using the full key (43 characters)
429 Too Many Requests
Cause: Rate limit exceeded
Solution:
- Implement exponential backoff
- Reduce request frequency
- Contact support for higher limits
Key Not Working Immediately
Note: New keys may take up to 5 seconds to propagate globally. Retry after a brief delay.
API Reference
List Keys (Console Only)
Keys cannot be listed via API for security reasons. Use the web console.
Validate Key
curl https://api.tokenlio.ai/v1/models \
-H "Authorization: Bearer $TOKENLIO_API_KEY"If valid, returns 200 OK with model list.
Migration Guide
From OpenAI
Replace:
client = OpenAI(api_key="sk-...")With:
client = OpenAI(
api_key="tk-...",
base_url="https://api.tokenlio.ai/v1"
)From Anthropic
Replace:
client = anthropic.Anthropic(api_key="sk-ant-...")With:
from openai import OpenAI
client = OpenAI(
api_key="tk-...",
base_url="https://api.tokenlio.ai/v1"
)
# Use OpenAI SDK with model="claude-3-5-sonnet"Support
Need help with API keys?
- Email: support@tokenlio.ai
- Documentation: /docs/
