DocumentationAPI keys

Get started

API keys

A key identifies your application to the API. Keep it on your server, like a password.

On this page
  1. What a key looks like
  2. Where to send it
  3. Get a key
  4. Keep it secret

What a key looks like

A key always starts with lya, followed by its type. The type says who it acts for.

PrefixTypeFor
lya_svc_ServiceAn application or server in your workspace
lya_usr_PersonalA person, with their own permissions
lya_prt_PartnerAn integration built with Learnya

Learnya keeps only a hash of it, which cannot be read back. A lost key cannot be recovered, only replaced.

Where to send it

In the Authorization header, after Bearer. The OpenAI SDKs do this for you. The x-api-key header is also accepted.

HeaderExample
AuthorizationBearer lya_svc_…
x-api-keylya_svc_…

A rejected key receives a 401 response, with no reason given. Someone trying keys therefore learns nothing.

Get a key

Keys are available to Team workspaces and partners. We create the key with you and choose together:

  • its name, to recognise it in your workspace
  • its scope, which must include llm:invoke to call the models
  • an expiry date if the key serves a time-limited project

The key is shown to you only once, when it is created.

Request a key

Keep it secret

  • One key per application, so you can revoke one without stopping the others
  • In an environment variable or a secrets vault, never in the code repository
  • A revoked key stops working in under a minute