DocumentationAPI keys
Get started
API keys
A key identifies your application to the API. Keep it on your server, like a password.
What a key looks like
A key always starts with lya, followed by its type. The type says who it acts for.
| Prefix | Type | For |
|---|---|---|
lya_svc_ | Service | An application or server in your workspace |
lya_usr_ | Personal | A person, with their own permissions |
lya_prt_ | Partner | An integration built with Learnya |
Learnya keeps only a hash of it, which cannot be read back. A lost key cannot be recovered, only replaced.
Where to send it
In the Authorization header, after Bearer. The OpenAI SDKs do this for you. The x-api-key header is also accepted.
| Header | Example |
|---|---|
Authorization | Bearer lya_svc_… |
x-api-key | lya_svc_… |
A rejected key receives a 401 response, with no reason given. Someone trying keys therefore learns nothing.
Get a key
Keys are available to Team workspaces and partners. We create the key with you and choose together:
- its name, to recognise it in your workspace
- its scope, which must include llm:invoke to call the models
- an expiry date if the key serves a time-limited project
The key is shown to you only once, when it is created.
Keep it secret
- One key per application, so you can revoke one without stopping the others
- In an environment variable or a secrets vault, never in the code repository
- A revoked key stops working in under a minute