Tokenify

Authentication

One header. Keys are bearer credentials, shown once, revocable in seconds.

Keys are shown once

We store a hash, not the key. When a key is created the full value is returned exactly once and never again — if it is lost, revoke it and create another. That is not an inconvenience we could remove: a key we could show you twice is a key an attacker could read out of our database.

A key is enough on its own to spend your balance. It carries no user identity and needs no second factor, which is why it belongs in an environment variable and never in a repository, a browser or a support ticket.

One key per service

Each key has its own rate limits and its own usage line, so you can see which service is spending and revoke one without restarting the others. Revocation takes effect across the fleet within seconds rather than at the end of a cache period.

SettingDefaultWhat it does
Requests per minute600Refused with 429 above this, per key.
Tokens per minute2,000,000Counted on the estimated prompt at admission.
Allowed modelsallRestrict a key to named models; anything else returns 403.

All three are editable per key from the keys page.

Test keys

A key created as a test key carries the tk-test- prefix. It behaves identically and bills identically — the prefix exists so that a key found in a log or a screenshot can be told apart at a glance from one that serves production.

Checking a key

The cheapest way to confirm a key works is to list models, which costs nothing and returns only what that key is permitted to call:

curl https://api.tokenify.dev/v1/models \
  -H "Authorization: Bearer $TOKENIFY_API_KEY"

Last updated 2026-09-28.