An API key says who may call the server. A licence says the server may serve a network. They are separate: a server on the network needs both, and refuses to serve the network without at least one key.
Issue a key
- Windows app: API keys → Add. Choose a label, an optional expiry, and optional limits.
- Command line:
aisuite-server-cli keys add --label "<name>".
The raw key is shown once. The server stores a salted PBKDF2-SHA256 hash, so it can check a key but never show it again. Lost a key? Revoke it and issue a new one.
| Plan | Keys |
|---|---|
| Free | None — Free serves this computer only, where no key is needed |
| Pro Personal | Up to 5 |
| Pro Commercial | Unlimited |
Send a key
Clients send the key as a bearer token, the way every OpenAI SDK does:
Authorization: Bearer <api-key>
The api-key and x-api-key headers are accepted too, for tools that use them. Requests on the server's own computer need no key when the server listens on this computer only.
Limit what a key can do
Each key can be narrowed. Limits are checked on the server, so a client cannot widen them.
| Limit | Command-line option | Effect |
|---|---|---|
| Expiry | --expires-days N | The key stops working after N days. |
| Models | --allow-model <id> (repeatable) | Only these models, on every endpoint that takes a model. |
| Endpoints | --allow-endpoint <category> (repeatable) | Only these kinds of request: chat, models, embeddings, images, audio, vision, pull. |
| Rate | --rpm N | Requests per minute for this key, overriding the server-wide limit. |
| Administration | --admin (app: Allow server administration) | May read usage for every key, export the audit log, watch request activity, scrape metrics and see gateway worker status. |
aisuite-server-cli keys add --label "marketing-chatbot" --allow-endpoint chat --allow-model llama3.2:3b --rpm 30 --expires-days 90
aisuite-server-cli keys add --label "prometheus" --admin
Note: New keys do not have administration rights. Give them only to monitoring tools and operators. Keys created before administration became a separate right keep it, so existing monitoring does not break; review and reissue those keys.
Daily request quotas and monthly budgets per key are governance settings (Commercial).
Rotate and revoke
- Issue the new key and give it to the client.
- Check on the Usage page that the old key has stopped being used.
- Revoke the old key: API keys → Revoke, or
aisuite-server-cli keys revoke <key-id>.
Revocation takes effect immediately; no restart is needed. aisuite-server-cli keys list shows ids, labels and expiry, never the keys.
Repeated wrong keys
The server slows down a client that keeps presenting wrong keys, so guessing keys is impractical. A client that is throttled gets 429 responses for a short time.
In a farm
A gateway and its workers have separate key stores:
- Client keys live on the gateway. Clients never see the workers.
- Worker keys live on each worker; the gateway presents them. A client key is not valid on a worker.
Questions
Can two people share a key? +
They can, but give each person, device and app its own key: usage and audit records are per key, and you can revoke one without disturbing the others.
Where are keys stored? +
In credentials/server-keys.json in the server's data folder, as salted hashes. On Linux the file is created readable by its owner only.
Do AI Suite apps need a key? +
Apps on the server's own computer do not. Apps on other computers ask for one when they connect.