Skip to Content
API AccessAuthentication

Authentication

API Access requests use Bearer token authentication with a Steinkauz AI API key.

API keys belong to the active organization when you create them. Keys created in an organization are organization resources; revoke them when an integration is retired or a member leaves.

API key format

Keys look like:

sk-steinkauz-live-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  • The prefix sk-steinkauz-live- identifies production keys.
  • The full secret is shown once when you create the key in Settings → API Keys.
  • We store only a hash of the key; we cannot recover a lost secret.

Request header

Authorization: Bearer sk-steinkauz-live-YOUR_SECRET

Example

curl -sS "$STEINKAUZ_BASE_URL/v1/models" \ -H "Authorization: Bearer $STEINKAUZ_API_KEY"

Store credentials in environment variables on the server that runs your integration (never commit real keys):

export STEINKAUZ_API_KEY="sk-steinkauz-live-..." export STEINKAUZ_BASE_URL="https://platform.steinkauz.ai"

Key hygiene

  • Treat API keys like passwords. Do not embed them in client-side code or public repositories.
  • Use server-to-server calls. API keys are not intended for browser-exposed applications.
  • Prefer one key per integration or environment; revoke keys you no longer use.
  • Rotate keys if a secret may have leaked; revoke compromised keys immediately in Settings → API Keys.
  • Choose inherit Budget mode (default) to debit your user Budgets, or dedicated to give the key its own optional caps.
  • Choose the API routing policy that matches the data that integration will send.

Access requirements

Your active organization must have a valid Cloud subscription to use inference. Private Deployment installs without Stripe billing skip the subscription and billing-period requirements:

  • BYOK / customer-owned Gateway: at least one configured provider with a valid API key in that organization; optional Steinkauz AI Budgets (no row = uncapped).

Requests authenticated with a valid API key are authorized independently of the web chat session but still respect entitlements and membership.

In organizations, only owners and admins can create API keys. See Members, roles & invites.

Configuration Audit

Creating a key, revoking it, or changing its Budget mode appears in Settings → Configuration Audit (and as five recent events on the API Keys page). The log stores the key prefix only, never the secret. See Configuration Audit.

Last updated on