API
Production Checklist
Prepare a direct API integration for reliable production use.
Before launch
- Create separate keys for development, staging, and production.
- Create keys in the correct personal or company account context.
- Keep all keys in a secret manager and test key rotation.
- Fetch the model list and verify every required capability.
- Set request, connection, and total operation timeouts.
- Add exponential backoff with jitter for temporary failures.
- Add an idempotency key to retryable completion requests.
- Add a stable session ID per conversation.
- Handle streamed error frames as well as HTTP error statuses.
- Monitor both
h5andweeklyusage windows. - Alert before quota reaches 100 percent.
- Enforce your own per-user limits before calling the API.
- Validate tool calls and structured output.
- Redact secrets and sensitive prompt content from logs.
- Store the request ID with each failure report.
Test failure cases
Test invalid and revoked keys, unknown models, empty messages, quota exhaustion, rate limiting, timeouts, a connection drop during streaming, duplicate idempotency keys, malformed tool arguments, oversized input, and a model without the requested capability. Confirm that your product gives the user a clear next action for each case.
