Getting Your API Key
- Sign up at kugelaudio.com
- Go to your Dashboard
- In the sidebar, open Team & Settings → API Keys
- Click Create key and give it a descriptive name (for example, “Production Server”)
- Copy and securely store your key
Using Your API Key
HTTP Requests
Include your API key in theAuthorization header using Bearer token format:
X-API-Key header:
api_key query parameter is also accepted, but use a header for HTTP
requests so the secret is less likely to appear in URLs and access logs.
WebSocket Connections
WebSocket connections accept the same credentials. PassAuthorization: Bearer
or X-API-Key in the handshake headers when your client library supports
custom headers:
SDK Usage
- Python
- JavaScript
- cURL
Environment Variables
For security, we recommend using environment variables instead of hardcoding API keys:KUGELAUDIO_API_KEY from your process environment as shown above. The Java
client also provides KugelAudio.fromEnv().
Traffic goes to the canonical geo-routed endpoint by default; see
Regions to pin traffic to the EU endpoint.
API Key Security
Never expose keys in client-side code
Never expose keys in client-side code
API keys should only be used in server-side code. Never include them in:
- Frontend JavaScript
- Mobile app source code
- Public repositories
- Client-side environment variables
Rotate keys regularly
Rotate keys regularly
Create new API keys periodically and delete old ones. This limits the impact of any potential key exposure.
Use separate keys for environments
Use separate keys for environments
Create separate API keys for development, staging, and production. This makes it easier to rotate keys and track usage.
Managing API Keys
Create keys as described in Getting Your API Key.Deleting Keys
If a key is compromised:- Create a new key and update your applications
- In Team & Settings → API Keys, click Delete on the old key and confirm
API-key lookups are cached briefly. A deletion can take roughly 30 seconds
to propagate to an ingress process, so rotate applications before deleting
the old key and do not rely on deletion as an instantaneous session kill.
Key Scope
Dashboard API keys are scoped to a project. Resource APIs such as dictionaries enforce that project scope.Authentication Errors
401 Unauthorized
error reads
"No credentials provided. Use ?api_key=, X-API-Key, or Authorization: Bearer."
Causes:
- No credentials in the request
- Invalid or deleted API key
- Malformed header format
- Send the key as
Authorization: Bearer YOUR_API_KEY,X-API-Key: YOUR_API_KEY, or theapi_keyquery parameter - Verify the API key is correct and has not been deleted
- For the EU endpoint, send the key without the
eu-prefix (only the SDKs strip it; see Regions)
403 Forbidden
- Trying to access resources from another account
- Using a key whose project does not own the requested resource
- Calling voice-management operations with a credential that has no organization/user identity
- Verify you’re using the correct API key
- Verify the key belongs to the resource’s project or organization
Testing Authentication
Verify your API key is working:200 voice-page response. A missing, invalid, or deleted
key receives the standard 401 UNAUTHORIZED error envelope. Do not use
/v1/models for this check: the model catalog is public and cannot verify a key.
Next steps
Quick Start
Make your first request with your new key
Errors
Every error code the API returns