Docs · Authentication

Authentication

JouleCloud authenticates API requests with an organization-scoped bearer token.

Organization keys

An organization can have several API keys, each with an optional label. Every key authenticates to the same org and bills to the same org budget. Your org starts with a default key, minted on demand the first time it is needed and stored server-side. Reveal or copy it from the console settings.

Owners and managers can mint additional labeled keys — for example, one per service or environment — and revoke any key individually; revoking one key leaves the others working. Members can view the key list but can't mint, rotate, or revoke. Manage keys from the console settings.

Using the key

Send it as a bearer token on every request:

Authorization: Bearer <your-org-key>

With the OpenAI SDKs, pass it as the api_key / apiKey and set the base URL to https://api.jouledns.com/v1.

Rotation

Rotating the default key mints a fresh one and revokes the old key immediately. Any client still using the previous key starts receiving 401 responses, so roll it out to your services before rotating. Rotate from the console.

Roles gate key management. Owners and managers can mint, rotate, and revoke keys. Members have read-only access: they can view and use the org's keys but can't change them.

Keeping keys safe