Authentication
Create an API key and authenticate your application.
Use an inference API key for model requests.
Create API key
- Sign in to the Tokamak workspace.
- Select the organization that will use and pay for the integration.
- Open API Keys and create an inference key.
- Save the key when it is shown.
Store it as TOKAMAK_API_KEY in your application's environment or secret manager. Keep it out of source control and public browser bundles.
Send the key
Add this header to API requests:
Authorization: Bearer YOUR_TOKAMAK_API_KEYFor example, list models:
curl -sS https://api.tokamak.sh/v1/models \
-H "Authorization: Bearer $TOKAMAK_API_KEY"The example uses Bash. API keys also support the X-API-Key header; use one credential header per request.
Select an environment
| Environment | API base URL |
|---|---|
| Production | https://api.tokamak.sh/v1 |
| Staging | https://api-stag.tokamak.sh/v1 |
| Local development | Your configured local gateway, followed by /v1 |
Create and use the credential for the intended environment. A local docs preview is not an API server.
For the Quickstart Python and JavaScript examples, set TOKAMAK_BASE_URL when using staging or a local gateway. In curl examples, replace the production base URL.
Manage keys
Give each integration a recognizable key name. Use the expiry shown by the workspace, and rotate keys before they expire.
To rotate a key, create a replacement in the same organization, update the application, verify a request and revoke the old key.
A key stays bound to its organization when you switch organizations in the browser. Management keys are for management operations and cannot be used for model requests.
If authentication fails
Check the API hostname, credential header, key expiry and whether the key has been disabled or revoked. If authentication succeeds but inference is refused, check that it is an inference key with a valid organization binding, available credit and applicable usage limits.
Continue with Quickstart or Errors and debugging.