Skip to content

Authentication

Generate, scope, and rotate AnyRouter API keys — bearer tokens, per-environment isolation, and bring-your-own-key.

AnyRouter uses bearer tokens. Every request carries an Authorization: Bearer <key> header, and one AnyRouter key reaches every model in the catalog — you never send an upstream provider key from your app.

Key format

AnyRouter-issued keys are prefixed with sk-ar-:

sk-ar-v1-abc123def456ghi789jkl012mno345pqr678stu901vwx

The prefix lets you tell AnyRouter keys apart from upstream provider keys in logs, git diffs, and secret scanners.

Sending the header

curl https://anyrouter.dev/api/v1/chat/completions \
  -H "Authorization: Bearer sk-ar-your-key" \
  -H "Content-Type: application/json" \
  -d '{"model": "openai/gpt-5.4-mini", "messages": [{"role": "user", "content": "hi"}]}'

The Anthropic Messages passthrough at /api/v1/messages accepts x-api-key instead of the bearer header — see the Messages API reference.

Creating keys

Open the API Keys dashboard and click Create key. You can set:

  • Name — a human label (e.g. production-backend, ci-smoketest).
  • Allowed models — optionally restrict the key to specific model ids.
  • Allowed endpoints — optionally restrict which API endpoints the key can call.
  • Expiry — an optional hard expiration date.
  • Rate limit override — cap requests per minute on this key.
  • Spend limit — optionally cap credits available to that key.

The full key is shown once. Copy it immediately and store it in your secret manager — AnyRouter only retains the prefix after the dialog closes.

Never commit keys to git. Use environment variables, a secret manager, or runtime injection. If a key leaks, rotate it immediately from the dashboard.

Rotating keys

Because AnyRouter keys are opaque and independent from upstream provider keys, rotation is zero-downtime — there's no need to coordinate with Anthropic, OpenAI, or any other provider.

Create a replacement key

Create a new key with the same restrictions and limits as the one you're replacing.

Deploy with the new key

Roll your application forward with the new key in its secret store.

Verify traffic moved

Confirm requests now flow through the new key in the usage dashboard.

Delete the old key

Once no traffic remains on the old key, delete it from the dashboard.

BYOK (bring your own key)

If you prefer to pay providers directly, attach your own provider credentials to AnyRouter under Dashboard → BYOK. Requests routed through your BYOK credentials are billed to your upstream account and reported separately from AnyRouter credits.

BYOK is ideal for:

  • Enterprises with existing upstream volume discounts.
  • Teams that need data residency guarantees tied to a specific provider region.
  • Users on provider-specific free tiers they want to preserve.

Base URL override

Some providers, such as Azure OpenAI or private OpenAI-compatible gateways, support custom endpoint URLs. If a provider supports this, you'll see a Base URL field in the BYOK configuration dialog. Enter your custom endpoint (for example, https://my-resource.openai.azure.com) to route requests through your own deployment. Preconfigured Gateway routes — such as OpenRouter, DeepSeek, xAI, and the Z.ai Standard/Coding Plan options — use their listed provider route instead of an arbitrary base URL override.

Key restrictions

SettingPurpose
allowed_modelsLimit the key to a fixed set of model ids.
allowed_endpointsLimit the key to specific API paths. Keys created in the dashboard grant the inference endpoints and leave management endpoints (keys, credits, logs, usage) off — turn them on in Permissions when you need them. Chat Completions, Messages, and Responses are one grant: a key allowed to call any of those three may call the others.
rate_limitSet requests per minute for that key.
limit + limit_resetCap credit usage for the key on a daily, weekly, or monthly cycle.
expires_atHard-expire the key at an ISO 8601 timestamp.

If you leave these fields unset, the key inherits the default account behavior.

I get a 401 Unauthorized

Check that your key starts with sk-ar- and is sent as Authorization: Bearer <key>. If the key was recently deleted or expired, create a new one from the dashboard. For the Messages endpoint, use the x-api-key header instead.

Related