API

Production Checklist

Prepare a direct API integration for reliable production use.

Before launch

  • Create separate keys for development, staging, and production.
  • Create keys in the correct personal or company account context.
  • Keep all keys in a secret manager and test key rotation.
  • Fetch the model list and verify every required capability.
  • Set request, connection, and total operation timeouts.
  • Add exponential backoff with jitter for temporary failures.
  • Add an idempotency key to retryable completion requests.
  • Add a stable session ID per conversation.
  • Handle streamed error frames as well as HTTP error statuses.
  • Monitor both h5 and weekly usage windows.
  • Alert before quota reaches 100 percent.
  • Enforce your own per-user limits before calling the API.
  • Validate tool calls and structured output.
  • Redact secrets and sensitive prompt content from logs.
  • Store the request ID with each failure report.

Test failure cases

Test invalid and revoked keys, unknown models, empty messages, quota exhaustion, rate limiting, timeouts, a connection drop during streaming, duplicate idempotency keys, malformed tool arguments, oversized input, and a model without the requested capability. Confirm that your product gives the user a clear next action for each case.