API keys
Create, limit, rotate and revoke API keys, including team keys with per-key spending limits and stage permissions.
An API key lets scripts, notebooks, the Python SDK and CI jobs use AutoData as you. Manage keys on the API Account page (/api_account) while signed in. Keys can't be managed with an API key.
Key format
dtpk_followed by 60 letters and digits. Lists show only the first 12 characters (the prefix).- AutoData stores only a one-way hash. The full key is shown once, when you create or rotate it.
Personal and team keys
Both kinds act as your account, and both spend your balance. A team key is a key you give to a colleague or a shared system. You can label it with an email and a description, and set spending limits and stage permissions when you create it. There are no separate member accounts. Personal and team keys share one limit on the number of active keys:
| Plan | Active keys |
|---|---|
| Trial | 1 |
| Paid | 3 |
| Unrestricted | 15 |
| Enterprise | 50 |
An administrator can raise the limit for your account. Revoked keys don't count toward it; expired keys do, until you revoke them.
Using a key
| Header | Notes |
|---|---|
Authorization: Bearer dtpk_… | Preferred |
X-API-Key: dtpk_… | Accepted wherever the Bearer form is |
curl -X POST https://your-server/api/v1/process \
-H "Authorization: Bearer $AUTODATA_API_KEY" \
-F "file=@customers.csv" \
-F 'config={"y_columns": ["label"]}'
| Status | Meaning |
|---|---|
| 401 | Missing, unknown, revoked or expired key (deliberately indistinguishable) |
| 403 | The key may not run a requested stage, or the session belongs to someone else |
| 429 | The key's daily or lifetime spending limit is reached |
A key can inspect itself. GET /api/v1/keys lists your active keys (never the secrets). GET /api/v1/usage returns the calling key's usage and remaining limits.
Creating a key
On the API Keys tab, type an optional name and click Generate Key. Keys created there never expire. To give a key a lifetime, call the endpoint from a signed-in session:
POST /api/account/api-keys
{"name": "nightly-export", "expires_in_days": 90}
expires_in_days takes 1 to 3650 days; 0 or no value means the key never expires. Team keys are created on the Team API Keys tab, or with POST /api/account/team-api-keys (fields name, email, description, daily_limit_usd, lifetime_limit_usd, tool_permissions). Team keys don't expire.
Spending limits and stage permissions
Edit on either tab, or PUT /api/account/api-keys/<key_id>, changes only the fields you send:
| Field | Type / default | Effect |
|---|---|---|
name, email, description | string | Labels |
daily_limit_usd | number, US dollars; unlimited (null) | Daily limit ($): the most the key may spend per day. The day resets at midnight UTC. |
lifetime_limit_usd | number, US dollars; unlimited (null) | Lifetime limit ($): the most the key may ever spend |
daily_credit_limit, lifetime_credit_limit | deprecated | Still accepted, in credits (the dollar amount × 1,000,000), and will be removed in a future version. Use the _usd fields. |
tool_permissions | allow_anomaly, allow_dtc, allow_mdh, allow_cds, allow_dsm, allow_dsg; all allowed | Which pipeline stages the key may run. At least one must stay allowed. |
Limits are checked when a run starts, and the cost is recorded when the run completes. A single large run can therefore take a key past its limit; the next run is then refused with 429. Spending limits and stage permissions apply to /api/v1/process, /api/v1/process-connector and automations. They are not yet enforced on /api/v1/inference and /api/v1/retraining, although spend there is still recorded against the key.
Rotating and revoking
- Rotate (
POST /api/account/api-keys/<key_id>/rotate) gives the key a new secret. It keeps its name, expiry, limits, permissions and history. The old secret stops working immediately, so update your clients straight away. - Revoke (
DELETE /api/account/api-keys/<key_id>) disables the key permanently and frees its slot. It can't be undone.
Usage per key
View usage on the Team API Keys tab (GET /api/account/team-api-keys/<key_id>/usage, for any key you own) shows:
- today's spend and requests;
- daily and lifetime spend against the limits, and what remains;
- the 7-day and 30-day daily averages;
- a 30-day chart of spend per day.
All amounts are US dollars. In the API response they are today_usd, daily_limit_usd, daily_remaining_usd, lifetime_spent_usd, lifetime_limit_usd, lifetime_remaining_usd, avg_daily_usd_7d, avg_daily_usd_30d and chart_data.usd (one value per day in chart_data.labels). A limit of null means no limit. The older credit-named fields are deprecated: still returned, equal to the dollar amount × 1,000,000, and due to be removed in a future version.
A request here means one completed, billed run. How runs are priced is explained in Account and billing.
Good practice
- Use one key per script or system, so you can cap it and revoke it on its own.
- Keep keys in a secret manager or environment variable, never in code or notebooks you share.
- Rotate keys regularly, and revoke keys you no longer use.