10
Management API
用管理用 key 以程式建立、修改、撤銷推論用 key。概念與 OpenRouter 的 provisioning key 相同。
兩種 key
推論用 key 呼叫模型(/chat/completions、/models、/generation…)。管理用 key 只能呼叫 /api/v1/keys 與唯讀的帳號端點(/key、/credits),不能呼叫模型,也沒有花費上限。在 Dashboard → API keys 勾選「管理用 key」即可建立。管理用 key 不能透過 API 建立,外洩時無法自我繁殖。
管理用 key 只看得到、也只能管理它所屬帳號的 key。用錯種類的 key 會得到 403,error_type = forbidden,並附 required_scope。
建立 key
POST /keys 帶 name,選填 limit(USD)與 limit_reset(daily / weekly / monthly)。回應只會包含一次完整 key,NXIO 只儲存雜湊。新 key 立刻可用。
curl https://api.nxioai.com/api/v1/keys \
-H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "ci-bot", "limit": 25, "limit_reset": "monthly"}'
# 201 {"data":{"hash":"3f2b…","name":"ci-bot","label":"sk-nxio-v1-9c1a...7e02","scope":"inference",
# "limit":25,"limit_reset":"monthly","disabled":false,"revoked":false,
# "key":"sk-nxio-v1-9c1a…7e02"}} <- plaintext, shown once列出與查詢
GET /keys 回傳有效的 key(含停用、不含已撤銷)。加 include_disabled=true 可連已撤銷的一起列出。GET /keys/{hash} 取單一 key。hash 是建立或列表回應中的 key id;完整 key 不會再回傳。
curl https://api.nxioai.com/api/v1/keys -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" curl "https://api.nxioai.com/api/v1/keys?include_disabled=true" -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" # include revoked
修改
PATCH /keys/{hash} 接受 name、disabled、limit(數字或 null 表示移除)、limit_reset(或 null 表示不重置)。停用立即生效,停用中的 key 會得到 401 直到重新啟用。已撤銷的 key 不能修改。
curl -X PATCH https://api.nxioai.com/api/v1/keys/3f2b… \
-H "Authorization: Bearer $NXIO_MANAGEMENT_KEY" \
-H "Content-Type: application/json" \
-d '{"disabled": true}' # or {"name": "…"}, {"limit": null}, {"limit_reset": "daily"}撤銷
DELETE /keys/{hash} 永久撤銷並立即停用。用量歷史仍歸屬該 key。管理用 key 不能撤銷自己,請到 Dashboard 操作。
curl -X DELETE https://api.nxioai.com/api/v1/keys/3f2b… -H "Authorization: Bearer $NXIO_MANAGEMENT_KEY"
# {"data":{"hash":"3f2b…","deleted":true}} revocation is permanent欄位
| 欄位 | 意義 |
|---|---|
| hash | Key id(uuid),用在 GET / PATCH / DELETE 的路徑。 |
| label | 顯示用的前後綴,例如 sk-nxio-v1-9c1a...7e02。 |
| scope | inference 或 management。 |
| limit | 本期 USD 花費上限,或 null。 |
| limit_reset | daily、weekly、monthly,或 null 表示不重置。 |
| disabled | 暫時停用(可恢復)。 |
| revoked | 已永久撤銷。 |
| last_used_at | 最後一次成功驗證的時間,或 null。 |