Authentication
Aikey365 API requests are authenticated with API keys.
Bearer token
Recommended for OpenAI-compatible endpoints:
http
Authorization: Bearer YOUR_API_KEYbash
curl https://aikey365.com/v1/models \
-H "Authorization: Bearer $AIKEY365_API_KEY"Anthropic style
The service recognizes common Anthropic headers:
http
x-api-key: YOUR_API_KEY
anthropic-version: 2023-06-01Gemini style
Gemini native requests can use:
http
x-goog-api-key: YOUR_API_KEYA key query parameter is also supported in applicable routes, but headers are generally safer for backend applications because URLs are more likely to appear in logs.
Key state and policies
Keys can be enabled, disabled, expired, or quota-exhausted. They may also carry model, IP, group, and routing restrictions.
Security
- Never commit keys to Git.
- Do not embed server keys in public frontend code.
- Do not put keys into URLs.
- Redact authentication headers from logs.
- Use separate keys per application and environment.
- Revoke leaked keys rather than simply hiding them.