# Going to production

> The checklist before serving real users - keys, shared balance, actual limits, errors, data, support - and the case of agencies.

Source : https://developers.tuk-ai.com/en/docs/production · Verified on 2026-10-04

## Checklist

- **A dedicated key** for the production application, separate from your trial and development keys.
- The key is **server-side** only (environment variable or secrets manager), never in a browser or a mobile app.
- The key allows **only the models used** by the application.
- A **monthly cap** is set on the key, at a level you are willing to lose if it leaks.
- The **account's entitlements** are monitored (credits, plan usage limits): they are shared with the app and the Studio, and nothing reserves them for your application (see below).
- Your code handles `402` (balance), `429` (rate or limits) and `5xx`, with bounded, spaced-out retries — see [Errors](https://developers.tuk-ai.com/en/docs/errors).
- Client-side timeouts are **long**: a generation can take more than a minute. Retrying too quickly produces a second, billed generation.
- You log the `x-request-id` header of each response, without logging the key.
- You know how to **revoke** the key and deploy a new one quickly.
- The chosen model still exists in the [catalog](https://developers.tuk-ai.com/models) (French), and you have planned what to do if it is withdrawn: Tukai never silently replaces one model with another.

## The actual limits

| Limit | Value | Enforced by |
|---|---|---|
| Rate per key, generation | 30 requests per minute | The API (`ratelimit-*` headers) |
| Rate per key, token counting | 300 requests per minute | The API |
| Monthly cap per key | The one you set | The API, before each generation call (UTC calendar month) |
| Your plan's usage limits | Those of your subscription | The API, as for the chat: shared with the app |
| Account balance | Your balance | The API (`402` when it runs out) |

There is currently **no** account-level spending cap, no spending alert, and no balance reserved for the API. Practical consequence: if the production application is critical, give it a Tukai account that is used for nothing else.

## Data

What happens to the content of your requests, what is kept and what is not: see [Data](https://developers.tuk-ai.com/docs/data) (French). For sensitive use, write to support **before** sending any data.

## Agencies and contractors

If you develop for a client:

- The Tukai account, the balance and the production keys must belong **to the client**. Create the keys from their account, never from yours.
- Never share your own key with a client, and do not reuse one client's key for another.
- When the project is handed over, the client revokes the keys you handled and creates new ones.
- The [terms of use](https://tuk-ai.com/legal/terms) provide for an invoice for each transaction, and an invoice in a company's name on request.

## Support and service status

- Support: [service-client@tukhnanutha.com](mailto:service-client@tukhnanutha.com) or +216 22 450 577. No response time is guaranteed.
- There is no public service status page yet. A series of `503` or `504` errors should be reported to support with the relevant `x-request-id` values.
