ml- so they’re easy to identify in logs and code reviews.
Creating a key
From the workspace UI: go to Settings → API Keys → New key. Choose the team, set optional per-key limits, and optionally set an expiry date. Via the API:Per-key limits
Per-key limits stack on top of team limits. A request is rejected if it would exceed either the key-level or team-level limit.| Limit | Description |
|---|---|
rpm_limit | Maximum requests per minute from this key |
tpm_limit | Maximum tokens per minute from this key |
budget_usd | Lifetime USD spending cap for this key |
expires_at | Hard expiry date — key stops working after this timestamp |
expires_at is useful for giving external contractors or integration partners time-bounded access. The key automatically stops working at the configured time without requiring manual revocation.
Giving different applications different access levels
A common pattern is to create one key per application or service:- Prod key — full RPM limit, moderate USD budget, 90-day expiry
- Staging key — lower RPM limit, small USD budget, no expiry
- CI key — very low RPM limit, tiny USD budget, no expiry
- Partner key — scoped to a specific model, hard expiry date
Rotating keys
When you need to rotate a key (for example, after a potential exposure):- Create a new key with the same team and limits.
- Update your application to use the new key.
- Delete or expire the old key.
Personal Access Tokens
In addition to service API keys, workspace users can create Personal Access Tokens (PATs) for their own API access. PATs are prefixed withml_pat_ and are scoped to the user’s team membership.
Next steps
- Organize keys into teams with shared limits
- Set up SSO & SCIM to automate user provisioning
- Monitor key usage in audit logs