- Workspace
- Its members share its API keys, its prepaid balance and its usage
- Keys
- Start with
dn_live_, are shown once, and work with both models and every endpoint - Roles
- Owner, Admin, Developer and Billing
- Test keys
- None: every key is live and billed. Try requests for free in the playground
- Where
- Console: Home, Playground, Usage, API keys, Billing and Settings
Workspaces#
A workspace is the unit of access and billing. Everyone in it shares its API keys, its prepaid balance and its usage charts, and every request any of its keys sends is drawn from the one balance. Rate limits are set per key, not per workspace, so give each service its own key and one backlog cannot slow another (see Rate limits). Rename a workspace under Settings; the name, 2 to 40 characters, shows in the sidebar and on receipts.
Members and roles#
| Role | May |
|---|---|
| Owner | Everything, including deleting the workspace |
| Admin | Manage keys, members, billing and settings |
| Developer | Create and revoke keys, read usage |
| Billing | Manage the balance, auto reload and invoices |
- Invite people by email under Settings, with the role they need. Give developers the Developer role and the finance team Billing.
- Change a role at any time from the members list.
- Removing a member ends their access to the workspace at once. Keys they created keep working until you revoke them, so revoke a person's keys when they leave, or rotate them as below.
API keys#
- Create a key under API keys and give it a name of up to 48 characters, such as the service that will use it. The full secret is shown once, when you create it. Store it in your secret manager or in the
DECISIONNODE_API_KEYenvironment variable straight away: afterwards the console keeps only its last four characters. - One key reaches everything. Keys are not scoped to a model or an endpoint: each works with both models,
/v1/decide, sessions, batch jobs and/v1/models. Batches and sessions belong to the key that created them. - Track use. The keys table shows who created each key, when, and when it was last used. Search by name, id or last four.
- Revoke a key from its row. Revoking is immediate and cannot be undone: the next call with it gets
401, and a session stream it connects closes with code4401. - Rate limits of each key, per model, are on the Rate limits tab, with how close the key came to them.
Rotating a key#
Rotate a key when someone who held it leaves, when it may have leaked, or on your own schedule. Two keys can be live at once, so rotation needs no downtime:
- 1.Create a new key, named for the service and the date.
- 2.Deploy it: put it in your secret manager and roll your service so every instance reads it.
- 3.Check the switch: the old key's last used stops moving, and Usage filtered by key shows traffic only on the new one.
- 4.Let what belongs to the old key finish: its open sessions, and the results of its batch jobs, which only the key that created them can read.
- 5.Revoke the old key.
Usage#
Usage charts spend, input tokens and requests for the workspace. Filter by model (or all models), by key (revoked keys included), and by range: 24 hours, 7 days or 30 days, read hourly (up to 7 days) or daily (7 days or more). Spend is input tokens times each model's price; output tokens are always 0. In code, usage.input_tokens on each response is exactly what that request billed.
Billing#
Billing holds the balance, top-ups, auto reload and one receipt per payment. What a request costs and how the balance works is on Pricing and billing.
Deleting a workspace#
Only the Owner can delete a workspace, under Settings, by typing its name to confirm. Every key stops working at once, the remaining balance is forfeited, and it cannot be undone. Download what you need first: receipts, usage, and the results of any batch jobs.
Creating a key means you accept the Terms of Service and the Acceptable Use Policy on behalf of your organisation.