Keys
Every request carries a key, and every key belongs to an organisation. That is what decides whose balance pays and whose logs it appears in.
Making one
Sign in at console.sociaro.com, open Keys, press Create key.
Give it a name that says where it will live — production, ci, alex's laptop — because that name
is what you will read later when deciding what to revoke.
The key is shown once. We store only its hash: if it is lost, the way forward is a new key, not recovery. Nobody at Sociaro can read it back to you, which is the same property that means nobody at Sociaro can leak it.
Using one
curl https://api.sociaro.com/v1/models \
-H "Authorization: Bearer $SOCIARO_API_KEY"
That lists every model the key may reach. A model absent from that list is a model this key cannot call, whatever the documentation says.
Revoking one
Revoke on the Keys tab stops a key immediately — anything using it fails on its next request. The key stays listed, because its past usage is part of your bill and deleting the row would not remove the spend.
Revoke a key the moment it might have leaked. There is no charge for making a new one, and rotating is cheaper than wondering.
What a key can reach
Keys have no spending limit of their own. The ceiling is the organisation's balance, shared by
every key it holds — so every key in an organisation reads the same figure, and any of them can
read it: GET /v1/balance answers {"remaining": 312.58}. See
balance and billing. One key overspending is therefore a
question about the organisation, not about that key.