Creating and managing AI API keys

Last updated 8 Oct 2026
View as Markdown

Overview

AI Inference API keys provide secure, programmatic authentication for applications calling the CloudPe AI Gateway at https://inferapi.cloudpe.com/v1. These keys carry the dedicated inference:invoke scope and cannot be used to manage virtual machines, storage volumes, billing settings, or other CloudPe cloud resources.

Inference keys are distinct from standard management API keys (see Creating and using API keys). While management keys grant administrative access to CloudPe APIs, inference keys are restricted exclusively to model inference. Both key types may use a cpk_ prefix in the dashboard; distinguish them by scope (inference:invoke for inference keys) rather than by prefix alone. You can scope each inference key to specific projects, set requests-per-minute (RPM), tokens-per-minute (TPM), and concurrency limits, and configure monthly spend caps to prevent unexpected budget overruns.

Each user may hold at most 10 active API keys in total (inference keys and console API keys share this cap).

Before you start

  • You need an active CloudPe account and an organization membership. See Creating your CloudPe account.
  • Account eligibility: Your organization must be KYC-verified or funded with a direct paid top-up (promotional or bonus credits do not qualify) before minting inference keys.
  • Creating, modifying limits for, or revoking inference keys requires the ai:keys permission.
  • Organization owners and administrators can view and manage all inference keys in the organization. Other members can view only the keys they created.
  • Review available models and token pricing in the model catalogue. See Browsing AI models and using the playground.
  • Track consumption and billing for inference keys in the usage dashboard. See Tracking AI usage and billing.

Steps

Create an inference API key

  1. In the sidebar, open API Keys under AI.
  2. Select Create key to open the dialog.
  3. Enter a descriptive key name in the name field.
  4. Optionally select one or more projects to restrict key usage to those project scopes. If omitted, the key operates across the entire organization.
  5. Optionally configure rate and budget limits:
    • Requests per minute (RPM)
    • Tokens per minute (TPM)
    • Concurrency limit
    • Monthly spend cap in currency units
  6. Select Create.
  7. In the modal, copy the plaintext secret key. Store it securely in your secret manager or environment configuration. Plaintext keys start with cpk_ and are shown only once.
  8. Select Done to close the dialog.

Edit limits or revoke a key

  1. In the sidebar, open API Keys under AI.
  2. Locate the key in the table:
    • To adjust rate limits or spend caps, select Edit limits, update the desired parameters, and select Save.
    • To revoke a key, select the delete button and confirm. Once revoked, applications using the key stop functioning within about a minute.

API

Console management endpoints on https://app.cloudpe.com require a signed-in dashboard session or a console API key. Inference keys carry only inference:invoke and work exclusively on https://inferapi.cloudpe.com/v1—they cannot call these management routes.

Method and path Permission Console API key
GET /api/v1/ai/keys ai:keys Unrestricted console key only (scoped keys with ai:keys return 403 today)
POST /api/v1/ai/keys ai:keys Not supported (use dashboard session)
PATCH /api/v1/ai/keys/{key_id} ai:keys Scoped console key with ai:keys, or dashboard session
DELETE /api/v1/ai/keys/{key_id} ai:keys Not supported (use dashboard session)

List active inference keys (unrestricted console API key or dashboard session):

curl https://app.cloudpe.com/api/v1/ai/keys \
  -H "Authorization: Bearer <UNRESTRICTED_CONSOLE_API_KEY>"

Create and revoke inference keys in the dashboard (API Keys under AI). POST /api/v1/ai/keys and DELETE /api/v1/ai/keys/{key_id} reject console API keys by design.

Update rate limits for an existing key:

curl -X PATCH https://app.cloudpe.com/api/v1/ai/keys/<key_id> \
  -H "Authorization: Bearer <CONSOLE_API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "rpm": 30,
        "concurrency": 2,
        "monthly_cap": 2500.00
      }'

Limits & billing

  • Inference keys authenticate requests via cryptographic hash verification against active cluster policies.
  • Plaintext key tokens are displayed only once upon generation and are never stored or recoverable in plaintext from the database.
  • Key rate limits are enforced independently across distributed gateway nodes.
  • Monthly budget caps reset on the UTC calendar month boundary (00:00 UTC). Crossing budget thresholds triggers automated email alerts to organization administrators.
  • Revoking an inference key terminates subsequent requests within about a minute (gateway authorization snapshots refresh on a 30-second interval) across all gateway nodes.

Troubleshooting

Message What it means What to do
maximum {…} active API keys reached Your user account has reached the shared cap of 10 active API keys (inference and console keys combined). Revoke unneeded keys before creating a new one.
API keys cannot create API keys A console API key was used for POST /api/v1/ai/keys. Create keys in the dashboard while signed in.
API keys cannot manage account credentials A console API key was used for DELETE /api/v1/ai/keys/{key_id}. Revoke keys in the dashboard while signed in.
AI_KEY_MINT_REQUIRES_KYC_OR_FUNDS Organization is not KYC-verified and has no qualifying paid wallet top-up. Complete KYC or add a direct paid top-up, then retry.
project_ids not in this organization One or more specified project identifiers do not belong to your active organization. Ensure all selected project IDs belong to your active organization.
key not found The requested inference key identifier does not exist or has already been revoked. Check the key ID or refresh the inference keys table.
Permission denied: 'ai:keys' required Your user account role does not have permission to manage AI inference keys. Request the ai:keys permission from an organization administrator.

FAQ

Can I use an inference key to call standard CloudPe management APIs? No. Inference API keys carry only the inference:invoke scope and cannot access management endpoints like virtual machines, networking, or billing.

How do I authenticate requests to the AI Gateway? Pass your inference API key as a Bearer token in the Authorization header when making requests to https://inferapi.cloudpe.com/v1.

What happens when an inference key exceeds its rate limit or monthly cap? Requests exceeding configured limits receive an HTTP 429 response. Keys reaching their monthly budget cap are blocked until the cap is increased or resets at the next billing cycle.

Related

Did this guide answer your question?If you need customized assistance with your deployment, reach out to our team.
Contact Support