Documentation / API basics
Authentication
Every API route except the three noted below requires a Bearer key.
Authorization: Bearer <key>
Keys are created per client so a single bot can be cut off without touching the rest. They are stored on the machine and survive a restart — they have to: the spend cap is counted per key, and a registry that reset with the process would be a cap you could clear by restarting the node.
Routes that need no key
| Route | Why |
|---|---|
GET /v1/models | An OpenAI client must discover the catalog before it has a key. The data is sanitised instead — no operator, no pricing. |
GET /v1/receipts/:id | Whoever paid through a 402 has no key by definition. Demanding one would leave them unable to audit what they paid for. |
GET /v1/keys/panel | The bootstrap the browser panel uses to obtain its own key. |