Skip to main content
CarHub API keys authenticate your server, worker or trusted backend. Use the key that matches the environment you are calling.

Inference API keys

Use an organisation API key for /v1/* and /mcp.
Use a staging key to run real models and track their credit usage separately. Production and staging share the organisation’s live credits, files and limits. The classification comes from the key and appears on jobs as is_staging. See staging. The secret is shown once when you create or rotate a key. Store it in a secret manager. CarHub stores only a hash and later displays the key prefix.

API key permissions

New keys with missing or empty permissions have no business access. You can grant individual inference endpoints, licence access per SDK, job reading and upload access. Historical family scopes remain supported. A call outside the allowed scopes returns 403 scope_not_granted. Owners and administrators manage these permissions in API access. Click Permissions beside a key, select the required access, review the changes and click Save permissions. Search the inference endpoints and families to find the scopes you need. Rotation preserves the key’s permissions. For an SDK integration, grant sdk:{sdk}:write to issue, renew, regenerate and retrieve its licence, or sdk:{sdk}:read to retrieve an existing licence. General * access does not grant any SDK licence permission. Licence access does not grant inference, jobs or storage access. Use GET /v1/api-keys/self to inspect the authenticated key’s identity, organisation, environment, expiry and normalized permissions without exposing its secret. Every SDK is configured with an API key and an optional .jwt licence. If you do not supply a .jwt, the SDK obtains its licence automatically using the key’s explicit SDK permission. See SDK licences and permissions for automatic acquisition, permission choices and steps to download a .jwt from the Hub. Use a chk_test_ key while you build. It uses deterministic results and a separate test balance. See test mode.
The inference API intentionally does not return CORS headers. Call it from your server, worker or trusted backend—not directly from browser code.