Skip to content
TukaiDevelopers

Search the documentation

Console
Documentation menu

Guides

API keys

How a tuk_sk_ key works, how to create it, limit it, keep it safe and revoke it without losing its history.

Verified on 4 October 2026Markdown versionReport a problem on this page

A tuk_sk_… key authenticates a program, not a person. It only opens the generation and token counting operations of the compatible API. It gives no access to your account, your conversations, or the management of your keys.

Create a key

In chat.tuk-ai.com: settings, group Fournisseurs (Providers), tab Clés API (API keys). Each key has:

  • a name, to recognize it;
  • a list of allowed models, required: the key can only call those;
  • an optional monthly cap, in dinars (see Credits and billing).

The full value of the key is shown only once, at creation. Tukai keeps only a fingerprint of it: neither the screen nor support can retrieve it. If you lose it, create another one and revoke the old one.

The tukai CLI also creates a key for you during tukai login (see tukai CLI (French)).

What the key list shows

For each key: its name, its beginning (tuk_sk_…, the prefix), its models, its limit, its creation date, its last use and, where applicable, its revocation date.

There is no notion of environment ("test", "production") attached to the key. If you want to separate your uses, create one key per use and name them accordingly: the name is a label, not a boundary.

Keep a key safe

  • Keep it in an environment variable or a secrets manager, never in code or in a repository.
  • Never put it in code run by a browser or a mobile app: anyone who extracts it spends your balance.
  • One key per application and per machine: if one leaks, you revoke only that one.
  • Set a monthly cap on any key that runs unattended.

Revoke a key

In the key list, revoke any key that is no longer used or that may have leaked. The effect is immediate: the next request that presents it receives 401, and any application using it stops working.

The key stays in the list with its revocation date: the history of what it consumed is kept. A revoked key cannot be reactivated.