API

API Authentication

Protect API keys and charge requests to the intended personal or company account.

Authenticate every request

Send the API key as a bearer token.

Authorization: Bearer YOUR_API_KEY

A missing, invalid, expired, or revoked key returns 401. A suspended account or inactive company seat returns 403.

Choose the account before creating a key

An API key belongs to the personal or company account selected when you create it. Requests made with that key use that account's subscription, quota, and spend controls. An existing key does not change account when you switch accounts in the web, desktop, CLI, or VS Code interface.

Create a separate key for each account and environment. Use clear names such as acme-production, acme-staging, and personal-local. This makes revocation and usage review safer.

Keep keys private

  • Store keys in a secret manager or protected environment variable.
  • Never commit a key to Git.
  • Never send a secret key to browser or mobile client code. Call MaxLabs from your server.
  • Do not copy keys into logs, error reports, URLs, or analytics events.
  • Revoke a key immediately if it may have leaked.
  • Rotate production keys on a regular schedule.

MaxLabs shows the full key only when you create it. Copy it then and store it safely.