Authenticate API requests
Send your Arnict API key in the Authorization header. Use Bearer followed by a space and the complete key. Both model listing and chat completions require authentication.
http
Authorization: Bearer $ARNICT_API_KEY
Content-Type: application/jsonbash
curl "https://api.arnict.com/v1/models" \
-H "Authorization: Bearer $ARNICT_API_KEY"Create and revoke keys
Verify your account email before creating a key. Open API keys in the dashboard to create a named key or revoke one you no longer use. The dashboard shows a masked identifier after creation, not the full secret.
| Action | What to do |
|---|---|
| Create | Copy the key immediately and save it securely. |
| Replace a lost key | Create a new key, update your application and revoke the old key. |
| Respond to an exposed key | Revoke it, create a replacement and review recent usage. |
| Separate applications | Use a different named key for each application or environment. |
- Manage API keysCreate or revoke keys in your account.
Protect your credentials
- Keys currently grant inference access. They do not grant access to your dashboard session.
- Make API calls from your server. Do not embed a key in a public website, mobile app bundle or shared notebook.
- Use environment variables or a secret manager. Redact Authorization headers from application logs.
- Revoke unused keys and review usage for unexpected activity.
A masked key is not the full key
The shortened value shown in the dashboard cannot authenticate a request. If you no longer have the full value, create a replacement.
- Authentication errorsUnderstand invalid, revoked and expired key responses.
