Create a key
You create a key in the API dashboard. It starts withoc_sk_. Copy it when it appears, and keep it on your server.
Where the key goes
You can pass the key in either of these headers. One of them is enough.x-api-key is not blank, OverControl uses that value and leaves Authorization unused. The bearer token is used when x-api-key is missing or empty.
Scopes
Each key carries a set of scopes. A request goes through when the key includes the scope for that operation.
If the scope is missing, you’ll get HTTP 403 and the message
Forbidden.
Chat Completions, the models list, and Files return this body. The response includes X-Request-Id.
request-id, and the same identifier inside the JSON as request_id.
Model allowlist
Some keys are limited to a list of model IDs. A key with no list can call every model on the models page, andGET /v1/models returns that full list. A key with a list only sees the models on it.
If you call Chat Completions with a model the key is not allowed to use, you’ll get HTTP 403:
When the key is not accepted
You’ll get HTTP 401 and the messageInvalid API key if a request has missing key, a malformed Authorization value, and a key OverControl does not recognize.
On Chat Completions, the models list, and Files:
X-Request-Id header. On Messages, request-id and request_id are that same value.
