10
Management API
Create, update and revoke inference keys programmatically with a management key. Same idea as OpenRouter provisioning keys.
Two kinds of keys
Inference keys call models (/chat/completions, /models, /generation…). Management keys can only call /api/v1/keys and the read-only account endpoints (/key, /credits); they cannot run models and carry no spend limit. Create a management key in Dashboard → API keys by ticking “Management key”. Management keys cannot be created through the API, so a leaked one cannot mint more of itself.
A management key sees and manages only the keys of the account it belongs to. Requests with the wrong kind of key return 403 with error_type = forbidden and required_scope.
Create a key
POST /keys with a name and optional limit (USD) and limit_reset (daily / weekly / monthly). The response includes the plaintext key exactly once; NXIO stores only its hash. The new key is usable immediately.
curl https://api.nxioai.com/api/v1/keys \
-H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "ci-bot", "limit": 25, "limit_reset": "monthly"}'
# 201 {"data":{"hash":"3f2b…","name":"ci-bot","label":"sk-nxio-v1-9c1a...7e02","scope":"inference",
# "limit":25,"limit_reset":"monthly","disabled":false,"revoked":false,
# "key":"sk-nxio-v1-9c1a…7e02"}} <- plaintext, shown onceList and inspect
GET /keys returns active keys (disabled ones included, revoked ones excluded). Add include_disabled=true to see revoked keys too. GET /keys/{hash} returns one key. hash is the key id from the create or list response; the plaintext is never returned again.
curl https://api.nxioai.com/api/v1/keys -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" curl "https://api.nxioai.com/api/v1/keys?include_disabled=true" -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" # include revoked
Update
PATCH /keys/{hash} accepts name, disabled, limit (number or null to remove) and limit_reset (or null for never). Disabling takes effect immediately; a disabled key gets 401 until re-enabled. Revoked keys cannot be modified.
curl -X PATCH https://api.nxioai.com/api/v1/keys/3f2b… \
-H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"disabled": true}' # or {"name": "…"}, {"limit": null}, {"limit_reset": "daily"}Revoke
DELETE /keys/{hash} revokes a key permanently and disables it at once. Usage history stays attributed to it. A management key cannot revoke itself; do that in the dashboard.
curl -X DELETE https://api.nxioai.com/api/v1/keys/3f2b… -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY"
# {"data":{"hash":"3f2b…","deleted":true}} revocation is permanentFields
| Field | Meaning |
|---|---|
| hash | Key id (uuid); use it in the path of GET / PATCH / DELETE. |
| label | Prefix and suffix of the key for display, e.g. sk-nxio-v1-9c1a...7e02. |
| scope | inference or management. |
| limit | USD spend limit for the current period, or null. |
| limit_reset | daily, weekly, monthly, or null for never. |
| disabled | Temporarily blocked (reversible). |
| revoked | Permanently revoked. |
| last_used_at | Last successful authentication, or null. |