Authentication
Generate, scope, and rotate AnyRouter API keys — bearer tokens, per-environment isolation, and bring-your-own-key.
AnyRouter uses bearer tokens. Every request carries an Authorization: Bearer <key> header, and one AnyRouter key reaches every model in the catalog — you never send an upstream provider key from your app.
Key format
AnyRouter-issued keys are prefixed with sk-ar-:
sk-ar-v1-abc123def456ghi789jkl012mno345pqr678stu901vwx
The prefix lets you tell AnyRouter keys apart from upstream provider keys in logs, git diffs, and secret scanners.
Sending the header
curl https://anyrouter.dev/api/v1/chat/completions \
-H "Authorization: Bearer sk-ar-your-key" \
-H "Content-Type: application/json" \
-d '{"model": "openai/gpt-5.4-mini", "messages": [{"role": "user", "content": "hi"}]}'
The Anthropic Messages passthrough at /api/v1/messages accepts x-api-key instead of the bearer header — see the Messages API reference.
Creating keys
Open the API Keys dashboard and click Create key. You can set:
- Name — a human label (e.g.
production-backend,ci-smoketest). - Allowed models — optionally restrict the key to specific model ids.
- Allowed endpoints — optionally restrict which API endpoints the key can call.
- Expiry — an optional hard expiration date.
- Rate limit override — cap requests per minute on this key.
- Spend limit — optionally cap credits available to that key.
The full key is shown once. Copy it immediately and store it in your secret manager — AnyRouter only retains the prefix after the dialog closes.
Never commit keys to git. Use environment variables, a secret manager, or runtime injection. If a key leaks, rotate it immediately from the dashboard.
Rotating keys
Because AnyRouter keys are opaque and independent from upstream provider keys, rotation is zero-downtime — there's no need to coordinate with Anthropic, OpenAI, or any other provider.
Create a replacement key
Create a new key with the same restrictions and limits as the one you're replacing.
Deploy with the new key
Roll your application forward with the new key in its secret store.
Verify traffic moved
Confirm requests now flow through the new key in the usage dashboard.
Delete the old key
Once no traffic remains on the old key, delete it from the dashboard.
BYOK (bring your own key)
If you prefer to pay providers directly, attach your own provider credentials to AnyRouter under Dashboard → BYOK. Requests routed through your BYOK credentials are billed to your upstream account and reported separately from AnyRouter credits.
BYOK is ideal for:
- Enterprises with existing upstream volume discounts.
- Teams that need data residency guarantees tied to a specific provider region.
- Users on provider-specific free tiers they want to preserve.
Base URL override
Some providers, such as Azure OpenAI or private OpenAI-compatible gateways, support custom endpoint URLs. If a provider supports this, you'll see a Base URL field in the BYOK configuration dialog. Enter your custom endpoint (for example, https://my-resource.openai.azure.com) to route requests through your own deployment. Preconfigured Gateway routes — such as OpenRouter, DeepSeek, xAI, and the Z.ai Standard/Coding Plan options — use their listed provider route instead of an arbitrary base URL override.
Key restrictions
| Setting | Purpose |
|---|---|
allowed_models | Limit the key to a fixed set of model ids. |
allowed_endpoints | Limit the key to specific API paths. Keys created in the dashboard grant the inference endpoints and leave management endpoints (keys, credits, logs, usage) off — turn them on in Permissions when you need them. Chat Completions, Messages, and Responses are one grant: a key allowed to call any of those three may call the others. |
rate_limit | Set requests per minute for that key. |
limit + limit_reset | Cap credit usage for the key on a daily, weekly, or monthly cycle. |
expires_at | Hard-expire the key at an ISO 8601 timestamp. |
If you leave these fields unset, the key inherits the default account behavior.
I get a 401 Unauthorized
Check that your key starts with sk-ar- and is sent as Authorization: Bearer <key>. If the key was recently deleted or expired, create a new one from the dashboard. For the Messages endpoint, use the x-api-key header instead.