Get started
Authentication
API keys
Create keys on the API keys page of the console. A key looks like rk_live_AbCd1234_...: a public prefix that identifies it in the console and request log, followed by a 32 character secret.
- The full key is shown once, when you create it. We keep only a SHA-256 hash, so a lost key cannot be recovered: create a new one.
- Revoking a key takes effect immediately. Requests that use it answer 401.
- Keys cannot create or change keys, webhooks or the Rogue connection. Those need a person signed in to the console.
Sending the key
Send the key as a bearer token. The X-API-Key header is accepted too, for tools that cannot set Authorization.
curl "https://rogue-api.sentryq-va.com/v1/account" \
-H "Authorization: Bearer $ROGUE_API_KEY"A missing, malformed, revoked or expired key answers 401 unauthorized. A valid key without the scope a route needs answers 403 forbidden.
Scopes
Pick the smallest set a key needs. New keys get every scope unless you untick some.
| Scope | Allows |
|---|---|
read | Read the account, models, projects, library and generations |
generate | Create generations and cost estimates (spends credits) |
uploads | Upload images, videos and audio |
projects | Create, rename and delete projects |
library | Favorite and delete items in the library |
A read-only key for dashboards
A key with only read can list models, projects, the library and generations, but can never spend credits.
Budgets, limits and expiry
Daily credit budget
A key can have a daily credit budget. Generations that would push the key past it answer 403 budget_exceeded before anything is sent to Rogue. The day resets at 00:00 UTC, and failed or canceled generations do not count.
Rate limit
By default each key may make 120 requests per minute. Every response reports X-RateLimit-Limit and X-RateLimit-Remaining; above the limit you get 429 rate_limited with a Retry-After header. See Rate limits and credits.
Expiry
Give a key a lifetime in days when you create it, for contractors, demos or short experiments. An expired key behaves like a revoked one.
The Rogue connection
When you sign in to the console, your password goes to Rogue once to open a session, and we keep only that session, encrypted. Every key you create uses it, and we refresh it automatically. If Rogue ends the session and it can no longer be refreshed, calls answer 403 connection_expired until you sign in to the console again. Your keys stay the same; nothing needs to be redeployed.
Each person in the console connects their own Rogue account, so their keys spend their own credits.
Keeping keys safe
- Keep keys on servers and in environment variables such as
ROGUE_API_KEY. Never ship them in browser or mobile app code. - Use one key per app or agent, so the request log shows who did what and you can revoke one without touching the others.
- Give agents a key with a daily budget, so a loop cannot drain the account.
- To rotate, create a new key, deploy it, then revoke the old one.