Authentication

Send your key as Authorization: Bearer <key> or x-api-key: <key> (Anthropic SDKs). Keys start with ugpt_live_ or ugpt_test_; test keys have low rate limits but bill real credits.

Harden keys on the API keys page: a monthly spend cap, a model allowlist, a lower RPM, an expiry, a read-only scope (no billed calls), an IP / CIDR allowlist, and — for keys used in a browser — allowed domains checked against Origin / Referer. Rotate a key to replace its secret with an optional grace period for the old one. A revoked key stops working immediately.