02
Authentication
Bearer API keys. Keys are scoped to your account, can carry spend limits, and are stored only as hashes.
API keys
Keys look like sk-nxio-v1- followed by 48 hex characters. Send them in the Authorization header as a Bearer token. NXIO stores only a SHA-256 hash, so a key cannot be recovered after creation.
Create, disable and revoke keys in Dashboard → API keys. A disabled key returns 401 immediately; revocation is permanent.
Authorization: Bearer sk-nxio-v1-4e672226fbe2…
Spend limits per key
Each key can have a USD limit that resets never, daily, weekly or monthly (UTC). When the projected cost of a request would exceed the remaining limit, the request is rejected with 402 and limit_source = nxio_key_limit. Check remaining limit with GET /key.
curl https://api.nxioai.com/api/v1/key -H "Authorization: Bearer $NXIO_API_KEY"
# {"data":{"label":"sk-nxio-v1-4e67...5805","limit":null,"limit_reset":null,"usage":0.0123,"usage_period":0.0123,"limit_remaining":null,"is_free_tier":false,"rate_limit":null}}Optional attribution headers
X-Title (or X-NXIO-Title) names your application; HTTP-Referer records its URL. Both appear in your usage analytics and help you split spend across apps. They are never forwarded to model providers.