Docs

Authentication

Every request carries an API key. The key identifies your account, its plan, and the tiers you can call.

Keys

  • Keys start with rl_. Keys issued before 2026-10-06 have an older prefix and keep working.
  • Keys are issued on request. Request access and the key arrives by email.
  • RouterLane stores only a SHA-256 hash of each key. A lost key cannot be recovered, only replaced.
  • Keep keys on servers and in developer machines' environment. Never ship one in a browser bundle or a mobile app.

Sending the key

Use either header. The OpenAI SDKs send Authorization: Bearer, the Anthropic SDKs send x-api-key, and RouterLane reads both on every endpoint.

shell
curl https://api.routerlane.com/v1/models \
  -H "x-api-key: $ROUTERLANE_API_KEY"

Claude Code sends the key from ANTHROPIC_AUTH_TOKEN as a bearer token, and Codex reads it from the variable named in env_key. See Integrations.

Plans and tiers

A key belongs to an account, and the account has a plan. The plan decides which tiers the key can call and how fast.

PlanTiersRequests a minuteConcurrent requestsTokens a month
Starterfast, normal60420M
Profast, normal, smart30016no cap
Enterpriseall four, including smart-pluscustomcustomcustom

GET /v1/models with your key lists exactly the tiers your plan includes. Calling a tier outside it returns 403.

Your default tier

An account has a default tier, Normal unless you ask for another. A request whose model is empty, auto or default runs on it.

Rotating and revoking

Email support@routerlane.com from your account's address to get a new key or revoke one. A revoked key is refused on its next request. To rotate without downtime, deploy the new key, then revoke the old one.

Errors

StatusTypeMessageCause
401authentication_errorinvalid or missing API keyNo key, an unknown key, or a revoked key
403permission_errorclient is suspendedThe account is suspended
403permission_errorthe smart tier is not included in plan Starter; available: fast, normalThe tier is outside your plan

The body follows the format you called. Anthropic format:

401, Anthropic format
{
  "type": "error",
  "error": {"type": "authentication_error", "message": "invalid or missing API key"}
}

OpenAI formats:

401, OpenAI formats
{
  "error": {
    "message": "invalid or missing API key",
    "type": "authentication_error",
    "code": "authentication_error"
  }
}

Smart+ job tokens

A Smart+ job uses its own token for the repository upload and the patch download. The router puts it in the commands it asks your agent to run, it works only for that job, and your API key never appears in them. See Smart+.