An API key says who may call the server. A licence says the server may serve a network. They are separate: a server on the network needs both, and refuses to serve the network without at least one key.

Issue a key

  • Windows app: API keys → Add. Choose a label, an optional expiry, and optional limits.
  • Command line: aisuite-server-cli keys add --label "<name>".

The raw key is shown once. The server stores a salted PBKDF2-SHA256 hash, so it can check a key but never show it again. Lost a key? Revoke it and issue a new one.

PlanKeys
FreeNone — Free serves this computer only, where no key is needed
Pro PersonalUp to 5
Pro CommercialUnlimited

Send a key

Clients send the key as a bearer token, the way every OpenAI SDK does:

Authorization: Bearer <api-key>

The api-key and x-api-key headers are accepted too, for tools that use them. Requests on the server's own computer need no key when the server listens on this computer only.

Limit what a key can do

Each key can be narrowed. Limits are checked on the server, so a client cannot widen them.

LimitCommand-line optionEffect
Expiry--expires-days NThe key stops working after N days.
Models--allow-model <id> (repeatable)Only these models, on every endpoint that takes a model.
Endpoints--allow-endpoint <category> (repeatable)Only these kinds of request: chat, models, embeddings, images, audio, vision, pull.
Rate--rpm NRequests per minute for this key, overriding the server-wide limit.
Administration--admin (app: Allow server administration)May read usage for every key, export the audit log, watch request activity, scrape metrics and see gateway worker status.
aisuite-server-cli keys add --label "marketing-chatbot" --allow-endpoint chat --allow-model llama3.2:3b --rpm 30 --expires-days 90
aisuite-server-cli keys add --label "prometheus" --admin

Note: New keys do not have administration rights. Give them only to monitoring tools and operators. Keys created before administration became a separate right keep it, so existing monitoring does not break; review and reissue those keys.

Daily request quotas and monthly budgets per key are governance settings (Commercial).

Rotate and revoke

  1. Issue the new key and give it to the client.
  2. Check on the Usage page that the old key has stopped being used.
  3. Revoke the old key: API keys → Revoke, or aisuite-server-cli keys revoke <key-id>.

Revocation takes effect immediately; no restart is needed. aisuite-server-cli keys list shows ids, labels and expiry, never the keys.

Repeated wrong keys

The server slows down a client that keeps presenting wrong keys, so guessing keys is impractical. A client that is throttled gets 429 responses for a short time.

In a farm

A gateway and its workers have separate key stores:

  • Client keys live on the gateway. Clients never see the workers.
  • Worker keys live on each worker; the gateway presents them. A client key is not valid on a worker.

Questions

Can two people share a key? +

They can, but give each person, device and app its own key: usage and audit records are per key, and you can revoke one without disturbing the others.

Where are keys stored? +

In credentials/server-keys.json in the server's data folder, as salted hashes. On Linux the file is created readable by its owner only.

Do AI Suite apps need a key? +

Apps on the server's own computer do not. Apps on other computers ask for one when they connect.