Skip to main content
You can cover model costs with OpenRouter API keys. Our API authenticates requests using Bearer tokens. This allows you to use curl or the OpenAI SDK directly with OpenRouter.
API keys on OpenRouter are more powerful than keys used directly for model APIs.They allow users to set credit limits for apps, and they can be used in OAuth flows.

Using an API key

To use an API key, first create your key. Give it a name and you can optionally set a credit limit.
For security, the full API key value (starting with sk-or-...) is only shown once, immediately after you create it. It cannot be retrieved later — the key settings page only shows a masked hash. Copy the key right away and store it somewhere safe (for example, an environment variable or password manager). If you lose it, delete the key at openrouter.ai/settings/keys and create a new one.
You can view, rename, disable, or delete existing keys at any time on the API keys settings page. To do the same programmatically, see Management API keys. If you’re calling the OpenRouter API directly, set the Authorization header to a Bearer token with your API key. If you’re using the OpenAI Typescript SDK, set the api_base to https://openrouter.ai/api/v1 and the apiKey to your API key.
To stream with Python, see this example from OpenAI.

If your key has been exposed

You must protect your API keys and never commit them to public repositories.
OpenRouter is a GitHub secret scanning partner, and has other methods to detect exposed keys. If we determine that your key has been compromised, you will receive an email notification. If you receive such a notification or suspect your key has been exposed, immediately visit your key settings page to delete the compromised key and create a new one. Using environment variables and keeping keys out of your codebase is strongly recommended.