Authentication
One header. Keys are bearer credentials, shown once, revocable in seconds.
The header
Authorization: Bearer tk-live-...Anthropic clients send x-api-key instead, and /v1/messages accepts it, so an Anthropic SDK configured with a Tokenify key works without a custom header.
Keys are shown once
We store a hash, not the key. When a key is created the full value is returned exactly once and never again — if it is lost, revoke it and create another. That is not an inconvenience we could remove: a key we could show you twice is a key an attacker could read out of our database.
One key per service
Each key has its own rate limits and its own usage line, so you can see which service is spending and revoke one without restarting the others. Revocation takes effect across the fleet within seconds rather than at the end of a cache period.
| Setting | Default | What it does |
|---|---|---|
| Requests per minute | 600 | Refused with 429 above this, per key. |
| Tokens per minute | 2,000,000 | Counted on the estimated prompt at admission. |
| Allowed models | all | Restrict a key to named models; anything else returns 403. |
All three are editable per key from the keys page.
Test keys
A key created as a test key carries the tk-test- prefix. It behaves identically and bills identically — the prefix exists so that a key found in a log or a screenshot can be told apart at a glance from one that serves production.
Checking a key
The cheapest way to confirm a key works is to list models, which costs nothing and returns only what that key is permitted to call:
curl https://api.tokenify.dev/v1/models \
-H "Authorization: Bearer $TOKENIFY_API_KEY"Last updated 2026-09-28.