What is relayfor.si?

Router keys

A key per agent, each spending one token's credit within its own limit. And the secret keys your server holds.

relayfor.si has two kinds of key. Never send one where the other belongs.

KeyStarts withMade onWho holds itWhat it does
Secret keyrf_sk_Dashboard: KeysYour serverRuns your project through the management API
Router keyrf_ai_Dashboard: Credit, or the APIAn agentCalls models on one token's credit

Both are shown once, when made. relayfor.si keeps only a hash of each, so a lost key can't be shown again: revoke it and make another. The one exception is a retry: a router key made with the API comes back to a retry of the same request within 24 hours.

Secret keys

Your server calls the management API with one. Make one for each server or service that calls it, so you can revoke one alone; a project has at most 10 that work. Keep them out of browsers, apps and code repositories.

Router keys

A router key spends one credit account, and that account belongs to one token. Give each agent its own key, so you can limit or revoke one alone. An account can have up to 100.

Make one on the dashboard (Credit, then the token's account, then New router key), or from your server:

curl https://relayfor.si/api/project/v1/keys \
  -H "Authorization: Bearer $RELAYFOR_SECRET_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{ "account": "<mint or acc_...>", "name": "agent-1", "limit": { "usd": "5", "reset": "daily" } }'

The answer carries the key (key). Store it as a secret where the agent runs, such as RELAYFOR_ROUTER_KEY: only a retry with the same Idempotency-Key within 24 hours shows it again.

Spending limits

A limit caps what one key may spend each period, from $0.01 to $1,000,000:

  • reset: daily, weekly or monthly, starting over at 00:00 UTC (weeks start on Monday).
  • A call whose reserve the key's remaining limit can't cover is refused with 402 key_limit, and the account's other keys keep working.
  • The first refusal in a period fires the key.limit_reached webhook.

Change a key's name or limit with PATCH /keys/{id}, or remove its limit with "limit": null. DELETE /keys/{id} revokes it: its next call is refused.

Keys in a browser

The RFS Router accepts calls from any origin, so a router key works in a browser app. Anyone who opens the page can read it there. Keep keys on a server when you can; when you can't, give the browser's key a small daily limit.

On this page