Inference API keys
Use an organisation API key for/v1/* and /mcp.
Use a staging key to run real models and track their credit usage separately. Production and staging share the organisation’s live credits, files and limits. The classification comes from the key and appears on jobs as
is_staging. See staging.
The secret is shown once when you create or rotate a key. Store it in a secret manager. CarHub stores only a hash and later displays the key prefix.
API key permissions
New keys with missing or empty permissions have no business access. You can grant individual inference endpoints, licence access per SDK, job reading and upload access. Historical family scopes remain supported. A call outside the allowed scopes returns403 scope_not_granted.
Owners and administrators manage these permissions in API access. Click Permissions beside a key, select the required access, review the changes and click Save permissions. Search the inference endpoints and families to find the scopes you need. Rotation preserves the key’s permissions.
For an SDK integration, grant sdk:{sdk}:write to issue, renew, regenerate and retrieve its licence, or sdk:{sdk}:read to retrieve an existing licence. General * access does not grant any SDK licence permission. Licence access does not grant inference, jobs or storage access.
Use GET /v1/api-keys/self to inspect the authenticated key’s identity, organisation, environment, expiry and normalized permissions without exposing its secret.
Every SDK is configured with an API key and an optional .jwt licence. If you do not supply a .jwt, the SDK obtains its licence automatically using the key’s explicit SDK permission. See SDK licences and permissions for automatic acquisition, permission choices and steps to download a .jwt from the Hub.
Use a chk_test_ key while you build. It uses deterministic results and a separate test balance. See test mode.