Documentation · Authentication

Getting started

Authentication

Every request is signed with an API key. Here is how to send it and how to keep it safe.

Send the key in the Authorization header with the Bearer scheme. For the Anthropic format the x-api-key header works too — that is what the official Anthropic SDK sends.

curl https://api.flua.ink/v1/models \
  -H "Authorization: Bearer $FLUA_API_KEY"

Managing keys#

  • Create a separate key for every project and environment.
  • Set a spending limit: once it is reached that key stops working, the others do not.
  • A revoked key stops working immediately.
  • The full key is shown once at creation; afterwards the dashboard only shows its last characters.

Security#

Never put the key into web pages or mobile apps — every user would see it. Call the API from your own server.
  • Keep keys in environment variables or a secret manager, never in git.
  • If a key leaks, revoke it and issue a new one.