Skip to main content

Authentication

How to authenticate your API requests

Requirements for API calls

All API requests to call any model on Model APIs require authentication with your API key. Pass it in either the X-API-Key header or the Authorization: Bearer header. Both are accepted on every endpoint, and the same key works for both.
Which header should I use?Either one. The examples in these docs use X-API-Key. The OpenAI SDK sends Authorization: Bearer automatically. If you send both headers, Authorization: Bearer takes precedence.
1

Create an Account

Sign up for a Nunchux account.
2

Generate an API Key

Go to your Dashboard and navigate to the API Keys section. Click “Create New Key” to generate a new API key, which you’ll use to securely access the API Reference.
Store your key securely — your API key is shown only once when created. Copy and store it in a secure location. If you lose it, you’ll need to generate a new one.
3

Set your API Key

Once you’ve generated an API key, set it as an environment variable.
Shell
4

Use the API Key

Include your API key in every request using the X-API-Key header.
Header format

Example Request

Best Practices

Store API keys securely

  • Use environment variables to store API keys
  • Never hardcode keys in your source code
  • Use secret management systems in production
  • Rotate keys periodically

Use environment-specific keys

Maintain separate API keys for different environments:
  • Development key for testing
  • Staging key for pre-production
  • Production key for live applications

Rotate a key

You can rotate a key from the dashboard without downtime. Open API Keys and select the rotate icon next to the key:
  • A new key is created with the same name and shown one time
  • The old key continues to work for 24 hours, then it stops
  • Update your applications to the new key in that window

Monitor API usage

Track your API usage to:
  • Detect unauthorized access
  • Optimize costs
  • Identify usage patterns
  • Plan capacity needs

Rate Limiting

Every key is limited per plan on requests per minute and simultaneous jobs; over a cap you receive a 429. The numbers and how to back off are on the Rate limits page.