Authentication
Every request carries an API key. The key identifies your account, its plan, and the tiers you can call.
Keys
- Keys start with
rl_. Keys issued before 2026-10-06 have an older prefix and keep working. - Keys are issued on request. Request access and the key arrives by email.
- RouterLane stores only a SHA-256 hash of each key. A lost key cannot be recovered, only replaced.
- Keep keys on servers and in developer machines' environment. Never ship one in a browser bundle or a mobile app.
Sending the key
Use either header. The OpenAI SDKs send Authorization: Bearer, the Anthropic SDKs send x-api-key, and RouterLane reads both on every endpoint.
curl https://api.routerlane.com/v1/models \
-H "x-api-key: $ROUTERLANE_API_KEY"curl https://api.routerlane.com/v1/models \
-H "Authorization: Bearer $ROUTERLANE_API_KEY"Claude Code sends the key from ANTHROPIC_AUTH_TOKEN as a bearer token, and Codex reads it from the variable named in env_key. See Integrations.
Plans and tiers
A key belongs to an account, and the account has a plan. The plan decides which tiers the key can call and how fast.
| Plan | Tiers | Requests a minute | Concurrent requests | Tokens a month |
|---|---|---|---|---|
| Starter | fast, normal | 60 | 4 | 20M |
| Pro | fast, normal, smart | 300 | 16 | no cap |
| Enterprise | all four, including smart-plus | custom | custom | custom |
GET /v1/models with your key lists exactly the tiers your plan includes. Calling a tier outside it returns 403.
Your default tier
An account has a default tier, Normal unless you ask for another. A request whose model is empty, auto or default runs on it.
Rotating and revoking
Email support@routerlane.com from your account's address to get a new key or revoke one. A revoked key is refused on its next request. To rotate without downtime, deploy the new key, then revoke the old one.
Errors
| Status | Type | Message | Cause |
|---|---|---|---|
| 401 | authentication_error | invalid or missing API key | No key, an unknown key, or a revoked key |
| 403 | permission_error | client is suspended | The account is suspended |
| 403 | permission_error | the smart tier is not included in plan Starter; available: fast, normal | The tier is outside your plan |
The body follows the format you called. Anthropic format:
{
"type": "error",
"error": {"type": "authentication_error", "message": "invalid or missing API key"}
}OpenAI formats:
{
"error": {
"message": "invalid or missing API key",
"type": "authentication_error",
"code": "authentication_error"
}
}Smart+ job tokens
A Smart+ job uses its own token for the repository upload and the patch download. The router puts it in the commands it asks your agent to run, it works only for that job, and your API key never appears in them. See Smart+.