# API keys and authentication > How to send your API key, keep it safe, and what each key can be limited to. Source: https://zurelay.com/docs/authentication Every request carries an API key. Keys belong to a workspace and spend its balance; each can be held to its own budgets, models and addresses. ## Sending the key Either header works on every endpoint: Headers: ``` Authorization: Bearer zr_live_your_key_here # or, as Anthropic's SDKs send it: x-api-key: zr_live_your_key_here ``` Keys start with `zr_live_`. You see the full key once, when you create it; we only keep a hash, so nobody (us included) can show it to you again. Lost it? Revoke it and make another. ## Keeping keys safe - Keep keys in a secret manager or environment variables, never in code or a repository. - Call zurelay from your server. A key in a browser or a mobile app can be read by anyone who has the app. - Use one key per app or environment (say, `production` and `staging`), so you can revoke one without touching the others. - Give each key only what it needs: a budget, the models it calls, the addresses it runs on. See [Key limits and rules](https://zurelay.com/docs/key-rules). - If a key leaks, revoke it under API keys. Requests with it stop within 15 seconds. ## What a key can be held to - `Monthly budget` (USD): Spend allowed per calendar month (UTC). - `Daily budget` (USD): Spend allowed per day (UTC). - `Rate limit` (requests / minute): Requests per minute; more are refused with 429. - `Expiry` (date): After it, the key stops working. - `Allowed models` (list): Only these models; anything else is refused with 403. - `Allowed IP addresses` (list): Only requests from these addresses or ranges. - `Smart routing` (setting): What happens when a model is down: see [Smart routing](https://zurelay.com/docs/smart-routing). ## Authentication errors | Status | Code | Means | | --- | --- | --- | | 401 | `missing_api_key` | No key in the request. | | 401 | `invalid_api_key` | The key doesn’t exist or was revoked. | | 401 | `expired_api_key` | The key passed its expiry date. | | 403 | `ip_not_allowed` | The key only works from other addresses. | | 403 | `model_not_allowed` | The key isn’t allowed to use this model. | | 402 | `insufficient_quota` | The workspace balance is empty. | > **Tip:** Every chat, image and video response carries an `x-request-id` header. Include it when you write to support and we can find the request in seconds.