Core concepts

Authentication

Every request is authenticated with a Roteo API key that starts with sk_.

Create a key

Sign in at app.roteo.ai, open Keys and create a key. The secret is shown only once, so copy it right away; it cannot be retrieved later. You can hold up to three active keys, and revoking one takes effect immediately while keeping its usage history.

A key can spend from your wallet. Keep it in an environment variable, never in source control or client-side code, and rotate it at once if it leaks.

Send the key

Send it on every request, either as x-api-key: sk_your_key or as Authorization: Bearer sk_your_key. Both work the same. The Anthropic and OpenAI SDKs send it for you once you set it on the client; see SDKs.

A missing or invalid key returns 401 unauthorized, and an inactive account returns 403 forbidden. See Errors.

Authentication | Roteo