API-Key Management

Q: How do I get an API Key?

A: Log in to the console → “API Keys” → “Create API Key” → enter a Key name → click “Create.”

Q: What should I do if my API Key is lost or compromised?

A: Take the following actions immediately:

  1. Log in to the console → “Key Management.”

  2. Find the affected Key → click “Disable” or “Delete.”

  3. Click “Create API Key” to generate a new Key.

  4. Update the Key configuration in your projects.

Recommendation: Do not hard-code your Key in source code. Use an environment variable to manage it instead.

For example: export OPENAI_API_KEY=sk-xxx

Q: Can I create multiple API Keys?

A: Yes. Each account can create multiple API Keys. We recommend creating separate Keys for different projects and environments, for example:

  • prod-key: Production environment

  • dev-key: Development and testing environment

  • team-a-key: Dedicated Key for Team A

This makes it easier to track usage and set quotas separately. If one Key is compromised, your other services will not be affected.

Q: How do I set a usage limit for an API Key?

A: Go to Console → “Key Management” → select the corresponding Key → “Quota Settings”:

  • You can set a daily credit limit, monthly credit limit, or total available quota.

  • When the limit is reached, requests made with that Key will return a 429 error.

  • The primary account is not affected by the quota limits assigned to sub-Keys.

Q: Do API Keys expire?

A: API Keys remain valid indefinitely by default and do not expire automatically. However, a Key will become invalid in the following situations:

  • The Key is manually disabled or deleted.

  • The account is suspended because of an outstanding balance or policy violation.

  • The account balance is exhausted.

We recommend rotating API Keys regularly, such as once every quarter, to improve security.