# API keys

> How a tuk_sk_ key works, how to create it, limit it, keep it safe and revoke it without losing its history.

Source : https://developers.tuk-ai.com/en/docs/authentication · Verified on 2026-10-04

A `tuk_sk_…` key authenticates a **program**, not a person. It only opens the generation and token counting operations of the compatible API. It gives no access to your account, your conversations, or the management of your keys.

## Create a key

In [chat.tuk-ai.com](https://chat.tuk-ai.com): settings, group **Fournisseurs** (Providers), tab **Clés API** (API keys). Each key has:

- a **name**, to recognize it;
- a list of **allowed models**, required: the key can only call those;
- an optional **monthly cap**, in dinars (see [Credits and billing](https://developers.tuk-ai.com/en/docs/billing#monthly-cap-per-key)).

The full value of the key is shown **only once**, at creation. Tukai keeps only a fingerprint of it: neither the screen nor support can retrieve it. If you lose it, create another one and revoke the old one.

The `tukai` CLI also creates a key for you during `tukai login` (see [tukai CLI](https://developers.tuk-ai.com/tools/cli) (French)).

## What the key list shows

For each key: its name, its beginning (`tuk_sk_…`, the prefix), its models, its limit, its creation date, its **last use** and, where applicable, its revocation date.

There is **no** notion of environment ("test", "production") attached to the key. If you want to separate your uses, create one key per use and name them accordingly: the name is a label, not a boundary.

## Keep a key safe

- Keep it in an environment variable or a secrets manager, never in code or in a repository.
- Never put it in code run by a browser or a mobile app: anyone who extracts it spends your balance.
- One key per application and per machine: if one leaks, you revoke only that one.
- Set a monthly cap on any key that runs unattended.

## Revoke a key

In the key list, revoke any key that is no longer used or that may have leaked. The effect is **immediate**: the next request that presents it receives `401`, and any application using it stops working.

The key stays in the list with its revocation date: the history of what it consumed is kept. A revoked key cannot be reactivated.

> **Logging out of the CLI does not revoke the key**
>
> `tukai logout` erases the key from your machine, but the key remains valid on Tukai's side. To disable it, revoke it in the key list.
