Authentication
API keys, per-key limits and app attribution.
Bearer keys
Every request to /api/v1/chat/completions, /api/v1/key, /api/v1/credits and /api/v1/generation must carry an Reroute key:
Authorization: Bearer sk-rr-v1-<64 hex characters>Keys are created in Settings → Keys. The secret is shown once at creation; afterwards only a label like sk-rr-v1-89c...3fa is visible, because we keep a SHA-256 hash and nothing else. A missing or unknown key answers 401 No auth credentials found.
/api/v1/models, /api/v1/models/…/endpoints, /api/v1/providers) are public and need no key.Per-key credit limits
A key can carry a credit limit in USD. Usage through the key is tracked separately from your account balance, and once it reaches the limit the key answers 402 This key has reached its credit limit. Disabling a key makes it answer 401 This API key is disabled until you enable it again. Both can be changed at any time without rotating the secret.
Inspecting a key
Check a key's usage and remaining limit from code:
curl https://reroute.wtf/api/v1/key \
-H "Authorization: Bearer $REROUTE_API_KEY"{
"data": {
"label": "sk-rr-v1-89c...3fa",
"usage": 0.0125,
"limit": 5,
"limit_remaining": 4.9875,
"is_free_tier": false,
"disabled": false
}
}| Field | Meaning |
|---|---|
label | Masked form of the key |
usage | USD spent through this key |
limit | Credit limit in USD, or null for unlimited |
limit_remaining | USD left before the limit, or null |
is_free_tier | true when the account balance is zero or below |
disabled | Whether the key is switched off |
App attribution
Two optional headers identify your app. Requests that send them are counted on the public app rankings.
| Header | Used as |
|---|---|
X-Title | Your app's display name |
HTTP-Referer | Your app's URL |