Authentication
API keys, the two accepted headers, and what a key can spend.
Keys
Create keys at Settings → API Keys. A key:
- looks like
chp_live_...and is shown once at creation, - is tied to your account and spends your account's credit balance,
- can be revoked at any time; revocation takes effect immediately.
Sending the key
Both header forms are accepted everywhere:
-H "Authorization: Bearer chp_live_..."
# or
-H "X-API-Key: chp_live_..."ChatGPT Actions use X-API-Key (its auth UI asks for a custom header name);
MCP clients use the bearer form.
Limits
- Up to 5 active keys per account.
- Keyed endpoints have no request rate limit beyond your credit balance and
duplicate-job protection. The keyless demo is limited per IP and answers
with
Retry-Afterwhen throttled.
Failures
Missing or invalid keys return the standard
error envelope with missing_api_key or invalid_api_key,
and billed is always false on auth failures. The message states the fix
and where to create a key.
Spend safety
- Submitting a job reserves processing credits and bills at completion, exactly once.
- Renders state their cost in the response before the clip exists.
- Re-rendering an already-rendered moment requires an explicit
force: true. - The keyless
/api/v1/demoendpoint spends nothing, ever.
Last updated on