Router keys
A key per agent, each spending one token's credit within its own limit. And the secret keys your server holds.
relayfor.si has two kinds of key. Never send one where the other belongs.
| Key | Starts with | Made on | Who holds it | What it does |
|---|---|---|---|---|
| Secret key | rf_sk_ | Dashboard: Keys | Your server | Runs your project through the management API |
| Router key | rf_ai_ | Dashboard: Credit, or the API | An agent | Calls models on one token's credit |
Both are shown once, when made. relayfor.si keeps only a hash of each, so a lost key can't be shown again: revoke it and make another. The one exception is a retry: a router key made with the API comes back to a retry of the same request within 24 hours.
Secret keys
Your server calls the management API with one. Make one for each server or service that calls it, so you can revoke one alone; a project has at most 10 that work. Keep them out of browsers, apps and code repositories.
Router keys
A router key spends one credit account, and that account belongs to one token. Give each agent its own key, so you can limit or revoke one alone. An account can have up to 100.
Make one on the dashboard (Credit, then the token's account, then New router key), or from your server:
curl https://relayfor.si/api/project/v1/keys \
-H "Authorization: Bearer $RELAYFOR_SECRET_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{ "account": "<mint or acc_...>", "name": "agent-1", "limit": { "usd": "5", "reset": "daily" } }'The answer carries the key (key). Store it as a secret where the agent runs, such as RELAYFOR_ROUTER_KEY: only a retry with the same Idempotency-Key within 24 hours shows it again.
Spending limits
A limit caps what one key may spend each period, from $0.01 to $1,000,000:
reset:daily,weeklyormonthly, starting over at 00:00 UTC (weeks start on Monday).- A call whose reserve the key's remaining limit can't cover is refused with
402 key_limit, and the account's other keys keep working. - The first refusal in a period fires the
key.limit_reachedwebhook.
Change a key's name or limit with PATCH /keys/{id}, or remove its limit with "limit": null. DELETE /keys/{id} revokes it: its next call is refused.
Keys in a browser
The RFS Router accepts calls from any origin, so a router key works in a browser app. Anyone who opens the page can read it there. Keep keys on a server when you can; when you can't, give the browser's key a small daily limit.