Get started

Authentication

Every request carries an API key. Keys belong to a person in the console and act on the Rogue account that person connected.

API keys

Create keys on the API keys page of the console. A key looks like rk_live_AbCd1234_...: a public prefix that identifies it in the console and request log, followed by a 32 character secret.

  • The full key is shown once, when you create it. We keep only a SHA-256 hash, so a lost key cannot be recovered: create a new one.
  • Revoking a key takes effect immediately. Requests that use it answer 401.
  • Keys cannot create or change keys, webhooks or the Rogue connection. Those need a person signed in to the console.

Sending the key

Send the key as a bearer token. The X-API-Key header is accepted too, for tools that cannot set Authorization.

curl "https://rogue-api.sentryq-va.com/v1/account" \
  -H "Authorization: Bearer $ROGUE_API_KEY"

A missing, malformed, revoked or expired key answers 401 unauthorized. A valid key without the scope a route needs answers 403 forbidden.

Scopes

Pick the smallest set a key needs. New keys get every scope unless you untick some.

ScopeAllows
readRead the account, models, projects, library and generations
generateCreate generations and cost estimates (spends credits)
uploadsUpload images, videos and audio
projectsCreate, rename and delete projects
libraryFavorite and delete items in the library

A read-only key for dashboards

A key with only read can list models, projects, the library and generations, but can never spend credits.

Budgets, limits and expiry

Daily credit budget

A key can have a daily credit budget. Generations that would push the key past it answer 403 budget_exceeded before anything is sent to Rogue. The day resets at 00:00 UTC, and failed or canceled generations do not count.

Rate limit

By default each key may make 120 requests per minute. Every response reports X-RateLimit-Limit and X-RateLimit-Remaining; above the limit you get 429 rate_limited with a Retry-After header. See Rate limits and credits.

Expiry

Give a key a lifetime in days when you create it, for contractors, demos or short experiments. An expired key behaves like a revoked one.

The Rogue connection

When you sign in to the console, your password goes to Rogue once to open a session, and we keep only that session, encrypted. Every key you create uses it, and we refresh it automatically. If Rogue ends the session and it can no longer be refreshed, calls answer 403 connection_expired until you sign in to the console again. Your keys stay the same; nothing needs to be redeployed.

Each person in the console connects their own Rogue account, so their keys spend their own credits.

Keeping keys safe

  • Keep keys on servers and in environment variables such as ROGUE_API_KEY. Never ship them in browser or mobile app code.
  • Use one key per app or agent, so the request log shows who did what and you can revoke one without touching the others.
  • Give agents a key with a daily budget, so a loop cannot drain the account.
  • To rotate, create a new key, deploy it, then revoke the old one.