API keys
Two kinds of key, optional spending limits and what to do if one leaks.
A key starts with binf_ and is followed by 40 letters and digits. Send it on every call as either header:
Authorization: Bearer binf_...
x-api-key: binf_...Two kinds of key
| Agent key | Account key | |
|---|---|---|
| Spends | The agent's own budget | Your account's credit |
| Filled by | The agent token's trading fees | BNB you pay, from 0.001 BNB |
| Who can make one | The wallet that launched the agent | Any signed-in wallet |
| Where | API keys, under the agent | API keys, under Account |
Both kinds call the same endpoints at the same prices. An agent's budget can only be spent by that agent's keys, and nobody can buy it: it comes only from trading.
Make a key
- Sign in on binference.io with the wallet that launched your agent, or any wallet for an account key.
- Press Create key and give it a name you'll recognize, like
prod-serverorlaptop. - Copy the key. It is shown once. We keep only a fingerprint, so a lost key can't be shown again: revoke it and make another.
You can have up to 10 active keys per agent, and 10 for your account.
Spending limits
Turn on Limit spending to cap what one key may spend per day, week or month, from $0.01 to $1,000,000. It is the safest way to give a key to a new tool or a teammate.
- Limits start over at 00:00 UTC. A weekly limit starts over on Monday.
- A key at its limit is refused with
402 key_limit, and the agent's other keys keep working. - A call counts in the period it started, however late it finishes.
- Setting a limit mid-period counts what the key already spent in it.
GET /balance shows the calling key's limit, what it spent and when it resets. See Get balance.
Revoke a key
Press Revoke next to it. It stops on its very next call: nothing is cached. A call already running finishes.
If a key leaks
Revoke it at once, then make a new one. A leaked key can spend its agent's whole balance, or its own limit. Never put a key in code that runs in a browser or a mobile app: keep it on your server.
Keep keys safe
- Read the key from an environment variable, never from source code.
- Give each tool or machine its own key, so you can revoke one without stopping the rest.
- Put a spending limit on keys for tests and for tools you're trying.