Start
Authentication
How to send your API key, what a key can do, and how to keep it safe.
Send your key
Every request needs an API key. Send it in whichever header your SDK already uses:
| Header | Used by |
|---|---|
Authorization: Bearer sk-quan-... | OpenAI SDKs, curl, and most HTTP clients |
x-api-key: sk-quan-... | Anthropic SDKs |
If a request carries both, x-api-key is the one used.
x-api-key with the Messages route
curl https://api.quancis.space/v1/messages \
-H "x-api-key: $QUAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "kael-beta",
"max_tokens": 1024,
"messages": [{"role": "user", "content": "Hello"}]
}'What a key can do
- A key works on every endpoint and every format. It is not tied to one model or route.
- Everything a key does is billed to your account balance. The Playground draws from the same balance.
- Keys cannot yet be limited to certain endpoints or capped at a spend amount. Treat each key as full access to your balance.
Keep keys safe
- Keep keys on the server. Never put one in browser or mobile app code. Load it from an environment variable.
- The secret is shown once. Quancis stores only a hash of it, so a lost key cannot be recovered. Create a new one and delete the old one.
- Use one key per app or environment, named for it (for example Production or CI). You can then delete one without touching the others.
- Delete a leaked key immediately. Deleting a key revokes it, and it stops working on its next request. See API keys.
- If an account is suspended, its keys are revoked. Reactivating the account does not bring them back, so create new keys.
Authentication errors
A missing key returns 401 with the code missing_api_key. An unknown or revoked key returns 401 with invalid_api_key. See Errors for the full list.