10

Management API

Create, update and revoke inference keys programmatically with a management key. Same idea as OpenRouter provisioning keys.

Two kinds of keys

Inference keys call models (/chat/completions, /models, /generation…). Management keys can only call /api/v1/keys and the read-only account endpoints (/key, /credits); they cannot run models and carry no spend limit. Create a management key in Dashboard → API keys by ticking “Management key”. Management keys cannot be created through the API, so a leaked one cannot mint more of itself.

A management key sees and manages only the keys of the account it belongs to. Requests with the wrong kind of key return 403 with error_type = forbidden and required_scope.

Create a key

POST /keys with a name and optional limit (USD) and limit_reset (daily / weekly / monthly). The response includes the plaintext key exactly once; NXIO stores only its hash. The new key is usable immediately.

POST /keys
curl https://api.nxioai.com/api/v1/keys \
  -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "ci-bot", "limit": 25, "limit_reset": "monthly"}'
# 201 {"data":{"hash":"3f2b…","name":"ci-bot","label":"sk-nxio-v1-9c1a...7e02","scope":"inference",
#      "limit":25,"limit_reset":"monthly","disabled":false,"revoked":false,
#      "key":"sk-nxio-v1-9c1a…7e02"}}   <- plaintext, shown once

List and inspect

GET /keys returns active keys (disabled ones included, revoked ones excluded). Add include_disabled=true to see revoked keys too. GET /keys/{hash} returns one key. hash is the key id from the create or list response; the plaintext is never returned again.

GET /keys
curl https://api.nxioai.com/api/v1/keys -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY"
curl "https://api.nxioai.com/api/v1/keys?include_disabled=true" -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY"   # include revoked

Update

PATCH /keys/{hash} accepts name, disabled, limit (number or null to remove) and limit_reset (or null for never). Disabling takes effect immediately; a disabled key gets 401 until re-enabled. Revoked keys cannot be modified.

PATCH /keys/{hash}
curl -X PATCH https://api.nxioai.com/api/v1/keys/3f2b… \
  -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"disabled": true}'            # or {"name": "…"}, {"limit": null}, {"limit_reset": "daily"}

Revoke

DELETE /keys/{hash} revokes a key permanently and disables it at once. Usage history stays attributed to it. A management key cannot revoke itself; do that in the dashboard.

DELETE /keys/{hash}
curl -X DELETE https://api.nxioai.com/api/v1/keys/3f2b… -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY"
# {"data":{"hash":"3f2b…","deleted":true}}   revocation is permanent

Fields

FieldMeaning
hashKey id (uuid); use it in the path of GET / PATCH / DELETE.
labelPrefix and suffix of the key for display, e.g. sk-nxio-v1-9c1a...7e02.
scopeinference or management.
limitUSD spend limit for the current period, or null.
limit_resetdaily, weekly, monthly, or null for never.
disabledTemporarily blocked (reversible).
revokedPermanently revoked.
last_used_atLast successful authentication, or null.