Platform

Key limits and rules

Hold each API key to what it’s for: how much it spends, how fast, which models, from where, and for how long. Set them when you create a key, or any time under API keys → Edit.

The rules

RuleWhat happens past itError
Monthly budget (USD)Requests are refused until the next month (UTC)402 key_budget_exceeded
Daily budget (USD)Refused until midnight UTC402 key_daily_budget_exceeded
Rate limit (requests a minute)Refused for a moment, with retry-after429 rate_limit_exceeded
ExpiryThe key stops working401 expired_api_key
Allowed modelsOther models are refused403 model_not_allowed
Allowed IP addressesRequests from elsewhere are refused403 ip_not_allowed

Refused requests are never charged. Budgets are checked before each request, so the request that crosses one still completes. Changes apply within 15 seconds, everywhere. Your workspace balance applies to every key: when it’s empty, requests get 402 insufficient_quota.

Allowed models

Pick any models, text, image or video. A key limited to, say, gpt-6-sol and gemini-3.7-flash can’t call anything else, and smart routing only uses alternatives from that list.

Allowed IP addresses

Single addresses and CIDR ranges, IPv4 and IPv6, up to 100 per key. The address checked is the one your request comes from on the internet (behind a proxy or NAT, that’s the proxy’s).

Examples
203.0.113.7 one address
198.51.100.0/24 a range of 256 addresses
2001:db8::/32 an IPv6 range
Serverless platforms and some clouds send requests from changing addresses. Use a range your provider publishes for egress, or leave IPs open on those keys and lean on the other rules.

Budgets in practice

  • Give every app or environment its own key and budget, so one runaway loop can’t drain the balance.
  • A daily budget catches a bug the same day; a monthly one caps the bill.
  • The API keys page shows each key’s spend today and this month next to its budgets.

Questions, or something missing? Ask support in your dashboard or email support@zurelay.com.