Account and API Keys
An API key identifies the caller, group, billing policy, and concurrency limits. A key can only access models published by its assigned group.
Create a key
- Sign in to the Codex Relay console.
- Open API Keys and select Create.
- Use a name that identifies the purpose, such as
macbook-codexorserver-bot. - Select a group. The group controls visible OpenAI models, rate policy, and the upstream pool.
- Set an expiration, quota, or model restriction when needed.
- Store the complete key as soon as it is created.
Never publish an API key
Do not place a real key in browser JavaScript, a Git repository, a screenshot, or documentation. Every example here uses the YOUR_API_KEY placeholder.
Validate a key
curl -i https://codexapi.asia/v1/models \
-H "Authorization: Bearer YOUR_API_KEY"A 200 response with a model list confirms that the domain, TLS connection, key, and group are working.
Authentication
| Use case | Recommended header |
|---|---|
| OpenAI SDK, Codex, and compatible clients | Authorization: Bearer YOUR_API_KEY |
Avoid query-string keys. Full URLs are more likely to appear in logs, browser history, and proxy records.
Use separate keys
- Give Codex, OpenAI SDK apps, desktop clients, and server jobs separate keys.
- Separate test and production environments.
- For temporary sharing, create a low-quota key with a short expiration and delete it afterward.
- If usage looks suspicious, revoke only the affected key.
Balance, subscriptions, and usage
The console shows balance, subscription progress, and request history. A request also depends on key status, user status, group availability, subscription quota, and concurrency limits. A positive balance alone does not guarantee that every model is available.
If a key is exposed
- Disable or delete the old key immediately.
- Create a replacement and update only the affected clients.
- Review timestamps, models, tokens, and source IPs in usage history.
- Contact the administrator with a request ID, never the complete key.
