# Key limits and rules > Monthly and daily budgets, rate limits, expiry, allowed models and allowed IP addresses for each API key. Source: https://zurelay.com/docs/key-rules Hold each API key to what it’s for: how much it spends, how fast, which models, from where, and for how long. Set them when you create a key, or any time under API keys → Edit. ## The rules | Rule | What happens past it | Error | | --- | --- | --- | | Monthly budget (USD) | Requests are refused until the next month (UTC) | `402 key_budget_exceeded` | | Daily budget (USD) | Refused until midnight UTC | `402 key_daily_budget_exceeded` | | Rate limit (requests a minute) | Refused for a moment, with `retry-after` | `429 rate_limit_exceeded` | | Expiry | The key stops working | `401 expired_api_key` | | Allowed models | Other models are refused | `403 model_not_allowed` | | Allowed IP addresses | Requests from elsewhere are refused | `403 ip_not_allowed` | Refused requests are never charged. Budgets are checked before each request, so the request that crosses one still completes. Changes apply within 15 seconds, everywhere. Your workspace balance applies to every key: when it’s empty, requests get `402 insufficient_quota`. ## Allowed models Pick any models, text, image or video. A key limited to, say, `gpt-6-sol` and `gemini-3.7-flash` can’t call anything else, and smart routing only uses alternatives from that list. ## Allowed IP addresses Single addresses and CIDR ranges, IPv4 and IPv6, up to 100 per key. The address checked is the one your request comes from on the internet (behind a proxy or NAT, that’s the proxy’s). Examples: ``` 203.0.113.7 one address 198.51.100.0/24 a range of 256 addresses 2001:db8::/32 an IPv6 range ``` > **Warning:** Serverless platforms and some clouds send requests from changing addresses. Use a range your provider publishes for egress, or leave IPs open on those keys and lean on the other rules. ## Budgets in practice - Give every app or environment its own key and budget, so one runaway loop can’t drain the balance. - A daily budget catches a bug the same day; a monthly one caps the bill. - The API keys page shows each key’s spend today and this month next to its budgets.