Keys and access
How to create an API key, limit models and spending, and revoke a key.
An API key works on behalf of an organization and spends its balance. Key limits are counted in rubles. Keys are created in the console, under "API keys".
A member sees, changes and revokes only their own keys. An organization owner and an administrator see and change all keys.
Create a key
- Open the form
Under "API keys", click "Create key".
- Name the key
The "Name" field is required, up to 100 characters. A separate key for each tool or service shows their spending on separate rows.
- Set the expiry, models and limits
All the fields below are optional. If the expiry is empty, the key does not expire.
- Save the secret
After creation, the key is shown in full once. You cannot recover it later, only issue a new one. The window closes with the "I saved the key" button.
If the form says "This feature is turned off in your organization", the "API keys" feature is off in the access settings. An owner or an administrator can turn it on.
Use a key
Put the key in an environment variable and pass it in the header:
export MORPHOGEN_API_KEY=mg-...
curl https://api.morphogen.ru/v1/models \
-H "Authorization: Bearer $MORPHOGEN_API_KEY"The x-api-key: <key> header is accepted too. Do not commit the key to a repository and do not print it in logs.
Models and limits
The "Full access" checkbox is on by default: the key works with all models of the organization, except those forbidden to the key owner. If you clear the checkbox, select the models in the list. At least one model is required.
Key limits:
| Field | Value |
|---|---|
| "Daily limit, ₽" | an amount in rubles, for example 500 or 12,5 |
| "Monthly limit, ₽" | the same for a month |
Limit rules:
- An empty field means "no limit". Zero means a zero limit: any paid request gets 402
key_limit_exceeded. This is how you freeze a key without revoking it. - Day and month are counted in Moscow time.
- A request is rejected if, together with it, the day or month spending would exceed the limit.
- Besides key limits, the spending limits of the employee, team and organization apply.
By default a key allows 120 requests and 200,000 tokens per minute. You cannot change the speed on the key page. More: Limits.
Change a key
Click the pencil icon in the key row. You can change the name, expiry, models and limits. "Project" and "Team" cannot be changed after creation. If you set a new date or clear the expiry of an expired key, it becomes active again. A revoked key cannot be changed.
Revoke a key
Click the trash icon in the key row and confirm. Requests with this key stop passing within a few seconds, and the action cannot be undone. Revoke a lost or compromised key and issue a new one.
When an employee leaves the organization, all their keys are revoked automatically. If the "API keys" feature is turned off for an employee later, the keys they issued stop working too: the API answers 401.
Key errors
| Code | Cause |
|---|---|
| 401 | the key is missing, invalid, revoked or expired |
403 model_not_allowed | the model is not in the key's list or is forbidden to the owner |
402 key_limit_exceeded | the daily or monthly key limit is used up |
402 spend_limit_exceeded | the spending limit of the employee, team or organization is used up |
All codes: Errors.