Authentication
JouleCloud authenticates API requests with an organization-scoped bearer token.
Organization keys
An organization can have several API keys, each with an optional label. Every key authenticates to the same org and bills to the same org budget. Your org starts with a default key, minted on demand the first time it is needed and stored server-side. Reveal or copy it from the console settings.
Owners and managers can mint additional labeled keys — for example, one per service or environment — and revoke any key individually; revoking one key leaves the others working. Members can view the key list but can't mint, rotate, or revoke. Manage keys from the console settings.
Using the key
Send it as a bearer token on every request:
Authorization: Bearer <your-org-key>With the OpenAI SDKs, pass it as the api_key / apiKey and set the base URL to https://api.jouledns.com/v1.
Rotation
Rotating the default key mints a fresh one and revokes the old key immediately. Any client still using the previous key starts receiving 401 responses, so roll it out to your services before rotating. Rotate from the console.
Keeping keys safe
- Store keys in environment variables or a secrets manager, never in committed source.
- The key authorizes spend against your org budget — treat it like a password.
- If a key leaks, rotate it from the console; the old key stops working at once.