Skip to content

Getting started

API keys

What an API key is, how to create one, what each option means, and how to view, disable, delete and protect your keys.

An API key is a string that starts with sk-. Programs and tools send it with every request to NoviaHub, so NoviaHub knows who is calling and whose balance to charge.

  • One account can have many keys. We recommend one key per app or tool, so if something goes wrong you only need to stop that one.
  • Each key can have its own expiry time, spending limit, allowed models and allowed IP addresses.
  • Calls are charged to your account balance, whichever key you use.

After signing in, open the console and click API Keys under General in the sidebar, or go straight to noviahub.com/keys.

The API Keys page: API Addresses and Create API Key buttons at the top, and a table of existing keys with their statusThe API Keys page: API Addresses and Create API Key buttons at the top, and a table of existing keys with their status
  1. Click Create API Key in the top-right. A panel opens on the right.

  2. Fill in the fields you need (most of the time only Name; leave the rest at their defaults):

    The Create API Key panel with Basic Information, Quota Settings and the expanded Advanced SettingsThe Create API Key panel with Basic Information, Quota Settings and the expanded Advanced Settings

    Basic Information

    Field Meaning
    Name Required, up to 50 characters. A label for yourself; naming it after its use helps, such as claude-code or my-app.
    Group Decides which group of routes and prices the key uses. If left empty, the key follows your account’s group (shown as User Group with an Inherited tag in the table). NoviaHub currently has a single group, the default group, so keep the default.
    Expiration Time Never expires by default. The quick buttons set Never, 1M (one month), 1 Day or 1H (one hour), or pick a date and time yourself. An expired key stops working.
    Quantity 1 by default. A number above 1 creates several keys at once, with a random suffix added to each name.

    Quota Settings

    Field Meaning
    Unlimited Quota On by default: the key itself has no spending limit. It does not mean free; calls are still charged to your balance and stop when the balance runs out.
    Quota Appears when Unlimited Quota is off. The most this key may spend, in the currency shown in the interface (usually US dollars, $). Once spent, the key’s status becomes Exhausted. Useful for test environments or keys you give to someone else.

    Advanced Settings (click to expand)

    Field Meaning
    Model Limits Only the selected models can be called with this key; empty means all models. Calling any other model returns a 403 error.
    IP Whitelist (supports CIDR) Only these IP addresses may use the key; empty means no restriction. Put one IP or range per line (such as 203.0.113.8 or 203.0.113.0/24); do not separate several addresses with commas on one line. The panel warns “Do not over-trust this feature. IP may be spoofed”, so treat it as an extra safeguard only.
  3. Click Save changes in the bottom-right. The new key appears in the list.

The list shows only the start and end of each key (such as sk-UD7q**********YDFZ). To get the full key, use any of these:

  • Click the masked key. A small Full API Key window opens with the text already selected; copy it.
  • Click the copy icon next to the key.
  • Click ⋯ at the right end of the row and choose Copy Key.

All three give you the full key, starting with sk-.

Clicking the masked key opens the Full API Key windowClicking the masked key opens the Full API Key window
Column Meaning
Name The name you gave the key.
Status See the statuses below.
API Key The key with its middle masked; click it to see the full key.
Quota ($) Unlimited for keys with unlimited quota; otherwise the remaining quota. Click it to see Remaining, Used, Current total quota and Remaining percentage. Current total quota = used + remaining.
Group The group the key uses.
Models “N models” when model limits are set, otherwise No restriction.
IP Restriction “N IP(s)” when an IP whitelist is set, otherwise No restriction.
Time When the key was created and last used.
Expires The expiry time, or Never.
Actions Enable/Disable, Edit and the ⋯ menu.

When the table is wide, scroll sideways to see the columns on the right.

Status When it happens Can it be used?
Enabled Normal state. Yes.
Disabled You clicked Disable. No. Click Enable to restore it.
Expired Its expiration time has passed. No. Edit the key and move the expiration time into the future, or set it to never expire.
Exhausted It has a quota limit and has spent it. No. Edit the key and raise the quota, or turn on Unlimited Quota.

Calling the API with a key whose status is not Enabled always returns HTTP 401 with the message Invalid token, without saying which of these reasons applies. When you get a 401, check the key’s status on this page first.

Each row ends with three buttons:

  • Disable / Enable: stop a key temporarily, or turn it back on. While disabled, calls with it return 401.
  • Edit: change the name, group, expiration time, quota, model limits and IP whitelist, then click Save changes.
  • ⋯ (Open menu): holds Copy Key, Copy Connection Info, CC Switch, Chat and Delete.
The ⋯ menu: Copy Key, Copy Connection Info, CC Switch, Chat and DeleteThe ⋯ menu: Copy Key, Copy Connection Info, CC Switch, Chat and Delete

What each menu item does:

Menu item What it does
Copy Key Copies the full key.
Copy Connection Info Copies a JSON text containing the key and NoviaHub’s address, in the form {"_type": ..., "key": "sk-...", "url": "https://noviahub.com"}. It lets another gateway of the same kind fill in a channel automatically; you normally won’t need it.
CC Switch Imports this key into CC Switch in one click; see CC Switch.
Chat Fills this key into a third-party chat app (such as Cherry Studio) in one click. The app must already be installed.
Delete Deletes the key permanently after a confirmation. This cannot be undone, and any program configured with the key stops working immediately.

Tick the checkboxes on the left to select several keys, then use Copy selected keys or Delete selected API keys.

The API Addresses button to the left of Create API Key lists the address to call (Default API address, https://noviahub.com) with a copy button. Each protocol uses the address a little differently; see Quickstart · Addresses.

  • One key per use: for example one for Claude Code and one for your own app. If one leaks or its usage looks wrong, disable just that one.
  • Cap keys you don’t fully trust: for keys lent to someone or used in a test environment, turn off Unlimited Quota, set a quota, and add an expiry time if needed.
  • Allow only the models you need: for a key used by a single tool, use Model Limits to allow only the models it needs, so an expensive model isn’t used by mistake.
  • Check regularly: in Usage logs, filter by Token Name to see each key’s calls and spending.