DocsAPI Reference

Quick start

Choose an organization, create a key, connect your application and verify the first request.


Use your operator's customer-app URL. For a local installation, first follow Installation. The app's Setup guide supplies the API endpoint for that deployment; the customer-app URL and API URL are different.

1. Sign in and choose an organization

Use an enabled login method or open your invitation. Check the organization shown in the selector. If you need a shared workspace, choose Create organization and finish provisioning before continuing.

Your role controls the pages and actions available. Ask an administrator if you need membership or billing access; creating a key does not grant those permissions.

2. Create an API key

Open the account menu at the foot of the sidebar, choose API keys, then Create API key:

  1. Give the key a name you will recognize.
  2. Check Permanent billing organization — this is the payer.
  3. Answer the team question: with one team it is preselected; with several, choose the team this key reports against or No team attribution. The choice cannot be changed later. Agent is optional.
  4. Create the key, then copy the one-time secret and store it securely.
Create API key dialog with key name, permanent billing organization, and team attribution fields.
Check the payer before creating the key. Account labels are examples; this form was not submitted. Open full size ↗

The key belongs to you; its payer and default team remain fixed when you switch organizations.

Use an inference key for model calls. A management key is a separate credential class and cannot invoke inference. Never put a secret in source control, a URL, a screenshot or a support message.

3. Check the endpoint and model

Open Setup guide from the sidebar. Find API base URL for SDKs and Available model. The generated connection example contains the exact model ID to use; a dropdown may show a friendly model name.

Setup guide with the organization selector at top left, API base URL for SDKs, available-model selector, and generated cURL example.
Staging Setup guide, with example account labels. Use the endpoint and model from your own deployment; navigation follows your permissions. Open full size ↗

You can also list models with your key. This example is for a local gateway; replace the base URL with your deployment's value.

export TOKAMAK_API_BASE='http://localhost:8080/v1'
export TOKAMAK_API_KEY='YOUR_API_KEY'
curl "$TOKAMAK_API_BASE/models" \
  -H "Authorization: Bearer $TOKAMAK_API_KEY"

Select a model that supports the request dialect you will use. If billing is enforced, the payer needs sufficient credit; applicable budgets must also allow the request.

4. Make a request

Replace MODEL_ID_FROM_CATALOG with an exact catalog ID. This call may consume the organization's credit.

curl "$TOKAMAK_API_BASE/chat/completions" \
  -H "Authorization: Bearer $TOKAMAK_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{"model":"MODEL_ID_FROM_CATALOG","messages":[{"role":"user","content":"Hello"}],"max_tokens":32}'

For an OpenAI-compatible client, use the same base URL, including /v1, and this key. See Bring your own client for SDK examples. For Anthropic Messages or Responses, use the corresponding dialect and a compatible model.

The path of a request
Your applicationTokamak key + catalog model ID
TokamakAuthenticate, check limits and route
Model providerRun the requested model
Credit admission also applies when billing is enforced.
The response returns through Tokamak to your client. Provider credentials stay on the server; usage becomes available in Analytics.

5. Confirm what happened

Open Analytics, choose Me, and check the organization and time range. Open Requests and inspect the request details when available. A created key alone does not establish a successful connection; look for the request you just made. Usage can take time to appear.

ResultNext action
401Check the credential, expiry and configured endpoint.
403Read the refusal code; verify permissions, payer and team membership.
402Check the payer's credit or debt with a billing administrator.
429Check applicable budgets and the reset window; other rate limits may also return 429.
503Retry or contact the operator; this is not evidence that you need more credit.

Prefer a coding tool?

One gateway, two URL formats
OpenAI-compatible SDKhttp://localhost:8080/v1Use as the client's base URL
Tokamak CLI loginhttp://localhost:8080Use with tokamak auth --api-url
Local example only. Copy your deployment's gateway address from Setup guide.

Use the installer offered by your deployment's Setup guide, then authenticate to its gateway URL without the /v1 suffix:

tokamak auth --api-url http://localhost:8080
tokamak auth status
tokamak launch claude
# Or: tokamak launch codex

CLI login creates its own credential through browser approval. It does not automatically reuse the manually created key above. Installer availability depends on published CLI artifacts. See Coding agents.

Next: invite colleagues, set a budget, or review credit.

On this page