Authentication

Create an API key, send it as a bearer token, keep it on your server, and read what a 401 is telling you.

Every request to the Jev AI API needs an API key. Create and manage keys in Settings → API keys.

Send a Bearer Token

Authorization: Bearer sk-glm5-...
curl https://jev-ai.org/api/v1/models/ \
  -H "Authorization: Bearer $JEV_API_KEY"

The x-api-key header is accepted as an alternative for clients that cannot set Authorization.

Keys begin with sk-glm5-. The plaintext is shown once, at creation, and only a hash is stored — if you lose it, rotate the key rather than asking support to recover it. The masked form in the dashboard (sk-glm5-51c9d1…6bc2) is a display label, not a usable credential.

Keys belong on your server

A Jev API key spends your token and credit balance. Never ship it in frontend JavaScript, a mobile bundle, a public repository, a screenshot, or an analytics payload. Put the call behind your own endpoint and let your server hold the key.

JEV_API_KEY=sk-glm5-your-key

Use One Key per Environment

Keys carry their own rate limit and their own daily decision budget, and each one can be revoked on its own. Separate keys turn an incident into a single revocation instead of a redeploy:

  • local-development
  • staging
  • production-ticket-router

What Does Not Cost Anything

Creating a key, listing keys, revoking a key and calling GET /api/v1/models never run the model and are never charged. Only POST /api/v1/systemone spends balance, and only when it succeeds.

When a Key Is Rejected

A rejected key always answers 401 with a reason field, which is the fastest way to tell the four cases apart:

reasonWhat happened
missing_bearerNo Authorization or x-api-key header arrived, or the scheme was not Bearer.
empty_tokenThe header was there but carried no key after the scheme.
unknown_keyThe key is not one of ours, or the masked display form was sent.
wrong_key_typeA management key was used on an inference endpoint.
disabledThe key exists and its owner can re-enable it.
revokedThe key exists but was permanently revoked.

A 401 is never a billing problem. If your balance is the issue you get a 402 instead, and the body says exactly how much was needed.