API keys and security

An API key authorizes requests to Aivrae. Use separate keys for separate apps, environments, or customers so they can be limited, rotated, and disabled independently.

  • Never publish production keys in frontend code, GitHub, public logs, or screenshots.
  • Use a separate low-limit key for test environments.
  • If a key is leaked, disable it immediately and create a new one.
  • For support, provide the key name or suffix only, never the full key.