Keys and authentication

Keys and authentication

API keys, the Authorization and x-api-key headers, SDK environment variables.

Every request is authorized with an API key. Keys are issued in the cabinet's Keys section; the key is stored encrypted and you can copy it at any time with “Show key”. The oldest keys, issued before this button existed, do not have it: if you lose such a key, issue a new one.

Headers

Pass the key in the Authorization: Bearer header — this is what OpenAI-compatible SDKs and Claude Code use:

bash
curl https://ai-seller.vibe-codes.ru/v1/models \
  -H "Authorization: Bearer $AISELLER_API_KEY"

The gateway also accepts the key in the x-api-key header — this is how the Anthropic SDK sends it. Both headers work on every endpoint.

$AISELLER_API_KEY in all examples is a placeholder. Put your own key from the cabinet in its place: the documentation never injects real secrets.

GET /v1/models works without a key. But if a key header is sent, the key must be valid: an invalid key gets 401 invalid_api_key.

SDK environment variables

The Anthropic SDK and Claude Code read the address and key from their own variables (the SDK appends /v1/messages itself):

bash
export ANTHROPIC_BASE_URL=https://ai-seller.vibe-codes.ru
export ANTHROPIC_AUTH_TOKEN=$AISELLER_API_KEY

The OpenAI SDK (Python and Node) reads the OPENAI_BASE_URL / OPENAI_API_KEY pair:

bash
export OPENAI_BASE_URL=https://ai-seller.vibe-codes.ru/v1
export OPENAI_API_KEY=$AISELLER_API_KEY

LiteLLM-based tools (such as aider) read OPENAI_API_BASE instead of OPENAI_BASE_URL. Ready-made configs are in Integrations.

Key safety

  • Do not commit the key to repositories or embed it in client-side code — pass it through environment variables or CI secrets.
  • A key can have a spend limit: once reached, new requests get 403 spend_limit_exceeded while your other keys keep working.
  • A compromised key can be revoked in the cabinet instantly; a revoked key cannot be restored — issue a new one.

Updated September 29, 2026