Developer Docs
API Keys
Browse documentation
Introduction
API Reference
Account & Billing
API keys are managed entirely from your APIonWeb dashboard — there is no API endpoint for creating or revoking keys themselves (that would be a bit circular). This page covers how keys work and how to manage them safely.
Creating a key
- Go to Dashboard → API Keys .
- Give the key a descriptive name (e.g. "production-backend" or "staging-worker") so you can tell keys apart later.
- Copy the full key immediately — it's displayed once, right after creation, and never shown again.
- Store it in a secrets manager or environment variable, not in source control.
Revoking a key
Revoke a key from the same dashboard page at any time. Revocation is immediate — any request made with
a revoked key afterward receives 401 invalid_api_key.
Revoking a key never affects your account balance or past usage history.
How many keys can I have?
You can create multiple keys per account — a common pattern is one key per environment (production, staging, local development) so you can revoke or rotate them independently without downtime elsewhere. All keys draw from the same account balance.
Best practices
- Keep keys server-side only — never ship one in client or mobile code.
- Use a separate key per environment so a leaked staging key doesn't affect production.
- Rotate keys periodically: create a new one, deploy it, then revoke the old one.
- Revoke a key immediately if you suspect it leaked — it's the fastest way to stop further spend.
Ready to call the API? Continue to Authentication or jump straight to the Virtual Try-On reference.