Authentication

Bearer authentication with sk-cf- keys: creation, budget caps, revocation, and how metering attributes spend per key.

Bearer keys

Authenticate every request with an Authorization header. Keys are created in the dashboard, shown once at creation, and start with sk-cf-.

Authorization: Bearer sk-cf-…

Per-key budget caps

Each key can carry a monthly budget cap, set from the dashboard in the same dollars as your balance and usage. Once the key's spend this calendar month (UTC) reaches its cap, calls with that key fail with HTTP 402 and the code key_budget_exceeded instead of accumulating surprise spend, the recommended setup for agents and CI.

The call that crosses the cap completes, so a reply is never cut off mid-stream, and every call after it is refused. Raising or removing a cap applies to the very next call, and caps reset on the 1st of each month. Requests that run on your own provider key (BYOK) cost you nothing here and do not count toward the cap.

Revocation

Revoke a key from the dashboard at any time. Treat revocation as propagation, not an instant kill: allow up to five minutes for a revoked key to stop validating everywhere.

Attribution

Usage is metered per key, so one key per agent, service, or teammate gives you cost per consumer as a dashboard filter instead of a spreadsheet.