Sociaro

Keys

Every request carries a key, and every key belongs to an organisation. That is what decides whose balance pays and whose logs it appears in.

Making one

Sign in at console.sociaro.com, open Keys, press Create key. Give it a name that says where it will live — production, ci, alex's laptop — because that name is what you will read later when deciding what to revoke.

The key is shown once. We store only its hash: if it is lost, the way forward is a new key, not recovery. Nobody at Sociaro can read it back to you, which is the same property that means nobody at Sociaro can leak it.

Using one

curl https://api.sociaro.com/v1/models \
  -H "Authorization: Bearer $SOCIARO_API_KEY"

That lists every model the key may reach. A model absent from that list is a model this key cannot call, whatever the documentation says.

Revoking one

Revoke on the Keys tab stops a key immediately — anything using it fails on its next request. The key stays listed, because its past usage is part of your bill and deleting the row would not remove the spend.

Revoke a key the moment it might have leaked. There is no charge for making a new one, and rotating is cheaper than wondering.

What a key can reach

Keys have no spending limit of their own. The ceiling is the organisation's balance, shared by every key it holds — so every key in an organisation reads the same figure, and any of them can read it: GET /v1/balance answers {"remaining": 312.58}. See balance and billing. One key overspending is therefore a question about the organisation, not about that key.