Authentication
API Access requests use Bearer token authentication with a Steinkauz AI API key.
API keys belong to the active organization when you create them. Keys created in an organization are organization resources; revoke them when an integration is retired or a member leaves.
API key format
Keys look like:
sk-steinkauz-live-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx- The prefix
sk-steinkauz-live-identifies production keys. - The full secret is shown once when you create the key in Settings → API Keys.
- We store only a hash of the key; we cannot recover a lost secret.
Request header
Authorization: Bearer sk-steinkauz-live-YOUR_SECRETExample
curl -sS "$STEINKAUZ_BASE_URL/v1/models" \
-H "Authorization: Bearer $STEINKAUZ_API_KEY"Store credentials in environment variables on the server that runs your integration (never commit real keys):
export STEINKAUZ_API_KEY="sk-steinkauz-live-..."
export STEINKAUZ_BASE_URL="https://platform.steinkauz.ai"Key hygiene
- Treat API keys like passwords. Do not embed them in client-side code or public repositories.
- Use server-to-server calls. API keys are not intended for browser-exposed applications.
- Prefer one key per integration or environment; revoke keys you no longer use.
- Rotate keys if a secret may have leaked; revoke compromised keys immediately in Settings → API Keys.
- Choose inherit Budget mode (default) to debit your user Budgets, or dedicated to give the key its own optional caps.
- Choose the API routing policy that matches the data that integration will send.
Access requirements
Your active organization must have a valid Cloud subscription to use inference. Private Deployment installs without Stripe billing skip the subscription and billing-period requirements:
- BYOK / customer-owned Gateway: at least one configured provider with a valid API key in that organization; optional Steinkauz AI Budgets (no row = uncapped).
Requests authenticated with a valid API key are authorized independently of the web chat session but still respect entitlements and membership.
In organizations, only owners and admins can create API keys. See Members, roles & invites.
Configuration Audit
Creating a key, revoking it, or changing its Budget mode appears in Settings → Configuration Audit (and as five recent events on the API Keys page). The log stores the key prefix only, never the secret. See Configuration Audit.