Manage teams, API keys, spending caps, and rate limits for your organization.
Teams group the people and credentials that share limits. API keys are the credentials your applications send as Authorization: Bearer ml-... to https://app.manylayers.io/v1. This page covers teams, admin-created API keys and their per-key limits; for finer-grained rules see Rate limiting, Budgets and Policies. Personal access tokens and virtual account tokens are covered in Credentials.In the console, keys live in Gateway → API Keys.
Teams are your primary isolation unit. Create a team for each department, project, or application that needs its own access controls and limits. Each team has:
Model allow-list (models) — which logical models the team can access, or *. A team with no list is unrestricted.
Rate limits — requests per minute (rpm_limit) and tokens per minute (tpm_limit); 0 is unlimited.
Monthly token budget (monthly_token_budget) — a cap on total tokens consumed in the calendar month, in UTC; 0 is unlimited.
Cache setting (cache_enabled) — opt in or out of response caching.
Firewall mode (firewall_mode) — override the gateway default: off, audit or enforce. See Prompt injection.
Default routing config (default_config_id) — which routing config applies to the team’s requests when the request names none.
List the organization’s teams, each with its models
POST
/admin/teams
Create a team, or update the one with the same name
Both are organization-level operations: they need the organization Owner (or the deployment operator credential). A workspace administrator manages the workspace’s own teams from Gateway → Access → Teams, and POST returns 409 team_in_workspace for a name that belongs to a workspace team.
Each API key is filed under exactly one organization team and can be bound to one workspace. A workspace-bound key resolves models from that workspace’s providers only; a key with no workspace_id is team-scoped. Limits stack: the key’s limits apply on top of the team’s and any policies, and the most restrictive one binds.Keys seeded from a self-hosted gateway.yaml take only a name, the key value and a role; the key is stored as a SHA-256 hash.
teams: - name: engineering api_keys: - name: dev key: ${MANYLAYERS_DEV_KEY} role: member
Per-key limits, budgets and expiry are set when you create or update a key through the admin API:
The response includes the new key as key (prefix ml-). It is shown once; only a hash is stored. team (or a user_id owner, whose own team is used) and name are required; role is member (default), editor or admin.
USD spending cap per budget period. Returns HTTP 402 when exhausted.
budget_reset_period
monthly
daily, weekly, monthly or never.
rpm_limit
0 (unlimited)
Requests per minute for this specific key
tpm_limit
0 (unlimited)
Tokens per minute for this specific key
expires_at
none
Hard expiry (RFC 3339). After this time, the key returns 401 key_expired.
PATCH /admin/keys/{id} replaces all limits at once. Any limit you leave out of the body is reset to 0 (unlimited) and expires_at is cleared, so always send the full set. name and workspace_id are only changed when you send them.