IsraelGPT API Docs Get an API key

Authentication

Every request to the public API carries an API key, sent as a bearer token. Keys belong to an account.

Getting a key

Make and manage keys on the dashboard, with a free IsraelGPT account. Name a key after what it's for and it's ready at once. There's no application to fill in.

An account can have up to 5 keys at a time. Revoke one to make room for another. Keys from before IsraelGPT was rebuilt no longer work: make a new one.

Sending it

Every request needs an Authorization header:

Authorization: Bearer igpt_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  • No header: 401 missing_api_key.
  • Something that isn't a key, or a key that doesn't exist or was revoked: 401 invalid_api_key.
  • 10 invalid keys in an hour from one address shut the API to that address for an hour (429). Guessing a key is hopeless anyway; this also stops a program that keeps retrying a revoked key.
  • A key whose account is suspended: 403 suspended, with the reason and how to appeal.

From a server, not a web page

The API has no CORS, so a browser won't let a web page call it, and every request with an Authorization header needs the browser's permission first. That's on purpose: a key in a web page or an app people download can be copied by anyone. Call the API from your own server, and have your page talk to your server.

Key format

Keys are igpt_ followed by 43 random characters. IsraelGPT keeps only a keyed hash of each key, plus its last four characters so you can tell your keys apart. The key itself is shown once, when it's made. If you lose it, there's no getting it back: revoke it and make a new one.

Per-key settings

Each key has a Media switch on the dashboard, on by default. Turn it off for an integration that only handles text: the model is told not to use [IMAGE], [music] or [podcast], any that slip through are taken out of reply, and there's no media. The change applies to the next request.

The request log

Open a key on the dashboard to see what it's been used for, newest first, for the last 30 days:

ColumnWhat it shows
WhenThe time of the request.
ResultThe HTTP status, and what happened: answered, blocked, crisis resources, bad request, over the limit, or the model failed.
ModelThe model and persona asked for.
TokensTokens in and out, as the model counted them.
TookHow long the answer took.
AppWhat the caller said it is, from its User-Agent: a library like Python (httpx), a tool like curl, or your own name like MyApp/1.0. Any program can claim to be anything, so it's a label, not proof.
FromThe network the request came from, as Cloudflare saw it, the country, and whether it's a data center (a server) or a home or mobile network. The address itself is never kept or shown.

What was said is never in the log. Refusals for going over a limit show at most once a minute, so a runaway loop can't flood it. If calls come from a network or app you don't recognise, the key has leaked: revoke it.

Keeping it safe

DoDon't
Keep it on your server (an environment variable or a secrets manager)Don't put it in a web page, a browser extension or an app people download
Use one key per app or botDon't share one key between unrelated projects
Revoke a key the moment you think it leakedDon't commit a key to a git repository
Check the request log now and thenDon't ignore calls from networks you don't recognise

Anyone with your key uses your allowance, and what they send is tied to your account. Revoking on the dashboard stops a key on its very next request.

Every key has an account

There's no guest tier: a key always belongs to a real account, so every key can use every persona, High effort and YahooBot 1. Limits are per key and per account (see Rate Limits), and a suspended account's keys stop working.