Authentication
Every API request uses a Bearer token created in your workspace.
Vergora uses API keys to authenticate API requests. Send requests from a server-side application and pass the credential in the
Authorizationheader.
Request header
Authorization: Bearer YOUR_VERGORA_API_KEYKeep one space between Bearer and the API key. Do not put an API key in a URL query parameter.
Create an API key
- Sign in to the console and open API Keys.
- Create a new API key.
- Use a name that identifies the application and environment, such as
storefront-production. - Configure its budget, expiration, and model access for the application.
- Follow the page instructions to copy and securely store the complete API key.
Configuration guidance
| Setting | Guidance |
|---|---|
| Name | Include the application and environment |
| Environment | Use separate keys for development, testing, and production |
| Budget | Set it for expected usage; a key budget does not add funds to the wallet |
| Expiration | Use a shorter period for temporary tests and review production keys regularly |
| Model access | Allow only the models required by the application |
| Source restrictions | If enabled, use the actual outbound address of the application |
Use the key in an application
export VERGORA_API_KEY="YOUR_VERGORA_API_KEY"Read the value from a server-side environment variable or secret manager. Never expose a complete key in source code, browser scripts, public repositories, logs, or screenshots.
Rotate or stop using a key
- Create a replacement key.
- Update the application and send a minimal request.
- Confirm the new request in Requests.
- Stop using the old key.
- Check that no application still uses the old credential.
If you lose the complete key, use the process provided in the console to create a replacement. If you suspect exposure, stop using the affected credential immediately and review related request records.
Troubleshoot authentication
| Check | Recommended action |
|---|---|
| The API key is empty or incomplete | Reload the server-side environment variable |
| The request header is invalid | Use Authorization: Bearer <key> |
| The key has expired or is no longer active | Check its status and create a replacement key |
| The budget or model scope blocks the request | Review the key policy and selected model |
| The request source is not allowed | Confirm the application's actual outbound address |
For a first integration, complete the Quickstart first.