Authentication

Quickstart, authentication, streaming, routing and error handling for the Autonomous Relay Agents API. OpenAI-compatible: change the base URL and the key.

Every request carries a bearer token. There are two classes of key, they are told apart by their prefix, and using the wrong one is the most common first error.

Authorization: Bearer <your key>

The two classes

  • ar-v1-… — inference. Makes model requests. This is the one that goes in your application.
  • ar-mgmt-… — management. Administers the account: keys, provider credentials, guardrails, credits. It cannot make an inference request.
The split is deliberate. An inference key is deployed widely — in containers, CI, a customer’s laptop — and if it could enumerate your provider credentials, every one of those places would be a way to reach them.

Key handling

  • Keys are stored as a salted hash. We cannot recover one, and neither can support.
  • A new key is shown once, at creation.
  • Revocation takes effect within seconds. You are responsible for spend before it.
  • Set a spend ceiling on every key. That is what bounds the cost of a leak.

Managing keys

GET/v1/keys
POST/v1/keys
DELETE/v1/keys/:hash

All three require a management key.

Checking a key

GET/v1/key

Returns the calling key’s own record — label, class, limit, usage. Useful as a health check that a deployed key is still live.

curl
curl https://autonomousrelay.com/v1/key -H "Authorization: Bearer $AGENTROUTER_API_KEY"