---
title: "Creating and managing AI API keys"
slug: "ai-api-keys"
source: "https://app.cloudpe.com/help/ai-api-keys"
updated: "2026-10-08T05:09:58.547Z"
---

# Creating and managing AI API keys

## Overview

AI Inference API keys provide secure, programmatic authentication for applications calling the CloudPe AI Gateway at `https://inferapi.cloudpe.com/v1`. These keys carry the dedicated `inference:invoke` scope and cannot be used to manage virtual machines, storage volumes, billing settings, or other CloudPe cloud resources.

Inference keys are distinct from standard management API keys (see [Creating and using API keys](/help/api-keys-management)). While management keys grant administrative access to CloudPe APIs, inference keys are restricted exclusively to model inference. Both key types may use a `cpk_` prefix in the dashboard; distinguish them by scope (`inference:invoke` for inference keys) rather than by prefix alone. You can scope each inference key to specific projects, set requests-per-minute (RPM), tokens-per-minute (TPM), and concurrency limits, and configure monthly spend caps to prevent unexpected budget overruns.

Each user may hold at most 10 active API keys in total (inference keys and console API keys share this cap).

## Before you start

- You need an active CloudPe account and an organization membership. See [Creating your CloudPe account](/help/account-signup-onboarding).
- Account eligibility: Your organization must be KYC-verified or funded with a direct paid top-up (promotional or bonus credits do not qualify) before minting inference keys.
- Creating, modifying limits for, or revoking inference keys requires the `ai:keys` permission.
- Organization owners and administrators can view and manage all inference keys in the organization. Other members can view only the keys they created.
- Review available models and token pricing in the model catalogue. See [Browsing AI models and using the playground](/help/ai-models-and-playground).
- Track consumption and billing for inference keys in the usage dashboard. See [Tracking AI usage and billing](/help/ai-usage-and-billing).

## Steps

### Create an inference API key

1. In the sidebar, open **API Keys** under **AI**.
2. Select **Create key** to open the dialog.
3. Enter a descriptive key name in the name field.
4. Optionally select one or more projects to restrict key usage to those project scopes. If omitted, the key operates across the entire organization.
5. Optionally configure rate and budget limits:
   - Requests per minute (RPM)
   - Tokens per minute (TPM)
   - Concurrency limit
   - Monthly spend cap in currency units
6. Select **Create**.
7. In the modal, copy the plaintext secret key. Store it securely in your secret manager or environment configuration. Plaintext keys start with `cpk_` and are shown only once.
8. Select **Done** to close the dialog.

### Edit limits or revoke a key

1. In the sidebar, open **API Keys** under **AI**.
2. Locate the key in the table:
   - To adjust rate limits or spend caps, select **Edit limits**, update the desired parameters, and select **Save**.
   - To revoke a key, select the delete button and confirm. Once revoked, applications using the key stop functioning within about a minute.

## API

Console management endpoints on `https://app.cloudpe.com` require a signed-in dashboard session or a console API key. Inference keys carry only `inference:invoke` and work exclusively on `https://inferapi.cloudpe.com/v1`—they cannot call these management routes.

| Method and path | Permission | Console API key |
|---|---|---|
| `GET /api/v1/ai/keys` | `ai:keys` | Unrestricted console key only (scoped keys with `ai:keys` return 403 today) |
| `POST /api/v1/ai/keys` | `ai:keys` | Not supported (use dashboard session) |
| `PATCH /api/v1/ai/keys/{key_id}` | `ai:keys` | Scoped console key with `ai:keys`, or dashboard session |
| `DELETE /api/v1/ai/keys/{key_id}` | `ai:keys` | Not supported (use dashboard session) |

List active inference keys (unrestricted console API key or dashboard session):

```bash
curl https://app.cloudpe.com/api/v1/ai/keys \
  -H "Authorization: Bearer <UNRESTRICTED_CONSOLE_API_KEY>"
```

Create and revoke inference keys in the dashboard (**API Keys** under **AI**). `POST /api/v1/ai/keys` and `DELETE /api/v1/ai/keys/{key_id}` reject console API keys by design.

Update rate limits for an existing key:

```bash
curl -X PATCH https://app.cloudpe.com/api/v1/ai/keys/<key_id> \
  -H "Authorization: Bearer <CONSOLE_API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "rpm": 30,
        "concurrency": 2,
        "monthly_cap": 2500.00
      }'
```

## Limits & billing

- Inference keys authenticate requests via cryptographic hash verification against active cluster policies.
- Plaintext key tokens are displayed only once upon generation and are never stored or recoverable in plaintext from the database.
- Key rate limits are enforced independently across distributed gateway nodes.
- Monthly budget caps reset on the UTC calendar month boundary (00:00 UTC). Crossing budget thresholds triggers automated email alerts to organization administrators.
- Revoking an inference key terminates subsequent requests within about a minute (gateway authorization snapshots refresh on a 30-second interval) across all gateway nodes.

## Troubleshooting

| Message | What it means | What to do |
|---|---|---|
| `maximum {…} active API keys reached` | Your user account has reached the shared cap of 10 active API keys (inference and console keys combined). | Revoke unneeded keys before creating a new one. |
| `API keys cannot create API keys` | A console API key was used for `POST /api/v1/ai/keys`. | Create keys in the dashboard while signed in. |
| `API keys cannot manage account credentials` | A console API key was used for `DELETE /api/v1/ai/keys/{key_id}`. | Revoke keys in the dashboard while signed in. |
| `AI_KEY_MINT_REQUIRES_KYC_OR_FUNDS` | Organization is not KYC-verified and has no qualifying paid wallet top-up. | Complete KYC or add a direct paid top-up, then retry. |
| `project_ids not in this organization` | One or more specified project identifiers do not belong to your active organization. | Ensure all selected project IDs belong to your active organization. |
| `key not found` | The requested inference key identifier does not exist or has already been revoked. | Check the key ID or refresh the inference keys table. |
| `Permission denied: 'ai:keys' required` | Your user account role does not have permission to manage AI inference keys. | Request the `ai:keys` permission from an organization administrator. |

## FAQ

**Can I use an inference key to call standard CloudPe management APIs?**
No. Inference API keys carry only the `inference:invoke` scope and cannot access management endpoints like virtual machines, networking, or billing.

**How do I authenticate requests to the AI Gateway?**
Pass your inference API key as a Bearer token in the Authorization header when making requests to `https://inferapi.cloudpe.com/v1`.

**What happens when an inference key exceeds its rate limit or monthly cap?**
Requests exceeding configured limits receive an HTTP 429 response. Keys reaching their monthly budget cap are blocked until the cap is increased or resets at the next billing cycle.

## Related

- [AI inference quickstart](/help/ai-inference-quickstart)
- [Browsing AI models and using the playground](/help/ai-models-and-playground)
- [Tracking AI usage and billing](/help/ai-usage-and-billing)
- [Creating and using API keys](/help/api-keys-management)