Authentication
Every request carries a key in the Authorization header:
Authorization: Bearer bea_sk_... Keys
- They are created, listed and revoked in the console, API keys section. Owners and admins of the organization can create them.
- They start with
bea_sk_and carry a checksum: a typo is recognized at once. - We store only a fingerprint (SHA-256), never the key: that’s why you see it only once.
- You can set an expiry (30, 90 or 365 days). A revoked key stops working at once.
Good practice
- Keep keys on the server or in an environment variable, never in code that reaches the browser or in a published app.
- One key per use (for example “Open WebUI”, “CI”, “production server”): if one leaks, you revoke only that one.
- Don’t share or resell keys: they act on behalf of your organization and usage is counted there.
When the key doesn’t work
| Response | Meaning |
|---|---|
401 missing_api_key | The Authorization header is missing |
401 invalid_api_key | Wrong, revoked or expired key |
403 organization_inactive | The organization is on the waitlist or suspended |
Full list in Errors.