Skip to content

DocsGetting started

Authentication

Every API request carries one of your API keys as a bearer token.

Header
curl https://api.avenro.tech/v1/credits -H "Authorization: Bearer $AVENRO_API_KEY"

API keys

  • Keys look like avenro_live_ followed by 43 letters and digits.
  • A key is shown once, when you create it. Avenro stores only a SHA-256 hash of it, so a lost key cannot be recovered: revoke it and create a new one.
  • Each key can have a spending limit. A request is refused when its reserved cost would take the key past the limit, which caps what a leaked key can spend.
  • Revoking a key in the dashboard stops new requests with it within seconds. Requests already running finish and are billed.

Keep keys on the server

Anyone with a key can spend your credits. Call the API from your backend, never from a browser or a mobile app, and keep keys out of source control.

Authentication errors

  • 401 missing_api_key: no Authorization: Bearer header.
  • 401 invalid_api_key: the key is malformed or does not exist.
  • 401 api_key_revoked: the key was revoked.
  • 403 account_disabled: the account is suspended; contact @avenrotech on X.

See Errors for everything else.