API Keys
A MiaRouter key is an sk-… string (prefix sk- plus 48 random characters). It authenticates relay traffic: chat completions, Claude messages, embeddings, audio, images — everything under /v1 and /v1beta. Your account can hold up to 50 keys (admin-configurable), so give every client its own.
Console → Keys ↗. The table lists each key masked; the full value is only shown when you reveal it, and only exists server-side in hashed form.
1Creating a key
- Press
Createon the Keys page. - Name it after the client that will use it — future-you debugs by name.
- Configure scope (below): quota, expiry, groups, model limits.
- Save. Reveal the key once and store it in your secret manager. If you lose it, you rotate it — nobody can read it back to you, by design.
2Scoping options
| Setting | What it does | Advice |
|---|---|---|
| Quota | Hard spend ceiling for the key, in credits. Unlimited delegates to your account balance. | Always set a ceiling for any key that leaves your machine. |
| Expiry | Fixed end time or never. | Expire keys you hand to temporary tooling. |
| Model limits | Allow-list of models this key may call. | Give cheap keys cheap models; keep the expensive tiers on your main key. |
| Group | Billing group the key routes through (e.g. default, vip, svip). Group ratios change effective price. | Default group unless you were told otherwise. |
| Auto-groups | Ordered group fallback list: try the first, fall back on failure. | For resilience across group tiers. |
| Cross-group retry | Retry a failed request in the next usable group automatically. | Leave on unless cost tiers must never mix. |
3Using the key
The relay accepts the key wherever the target wire format expects it:
| Client style | Header | Works on |
|---|---|---|
| OpenAI-style | Authorization: Bearer sk-… | everything |
| Anthropic-style | x-api-key: sk-… | /v1/messages, /v1/models |
| Gemini-style | x-goog-api-key: sk-… or ?key=sk-… | /v1beta/models…, /v1/models |
The gateway bridges these automatically — an Anthropic client with an x-api-key header is understood on Claude routes without any shimming.
4Key states
| State | Meaning | Fix |
|---|---|---|
| Enabled | Active. | — |
| Disabled | Manually off; requests get 401. | Re-enable after fixing whatever made you disable it. |
| Expired | Expiry time passed. | Extend expiry or create a successor. |
| Exhausted | Key quota hit zero. | Raise the quota or go unlimited (carefully). |
5Best practices, non-negotiated
- One key per client. Usage Logs attribute traffic by key; a shared key is an unattributable mess.
- Never paste keys into code, logs, or chat. Keys that leak are disabled the moment we see them in a log.
- Compromised? Disable it yourself, instantly. Row actions → disable. Then create a fresh one. Do not wait for support.
- Model-limit anything that touches expensive tiers. A stray agent loop calling
claude-fable-5-1all night is exactly why key quotas exist.
A key created inside a dedicated pool only works on that pool's subdomain (e.g. yourpool.miarouter.online) and is rejected on the main domain — and vice versa. See Platform Reference.