Skip to main content

Authentication

Every hosted inference route requires a valid KittenML API key.

Create or manage a key on the KittenML platform.

export KITTENML_API_KEY="sk_kitten_live_..."
Authorization: Bearer sk_kitten_live_...

Keep keys server-side​

Treat an API key like a password:

  • Store it in a secret manager or server environment variable.
  • Do not commit it to Git.
  • Do not place it in a query string, log message, analytics property, ticket, screenshot, browser bundle, or mobile binary.
  • Route browser and mobile requests through a backend you control. For browser microphones, use the short-lived WebRTC token flow.

Permissions and account state​

A key must be valid and authorized for the requested service. Upload and realtime STT require the asr:transcribe permission; KittenTTS requires the tts:generate permission.

Every model is authenticated, including models without a charge. Pricing and balances are on the KittenML platform.

Paid upload ASR checks the decoded file duration before inference. Realtime ASR checks an admission estimate and continues checking prospective usage as audio arrives. Successful completion is recorded using the final measured audio duration.

Authentication errors​

For HTTP and WebRTC signaling requests, missing or invalid credentials return 401:

{
"error": {
"message": "Invalid API key.",
"type": "authentication_error",
"param": null,
"code": "invalid_key"
},
"request_id": "<request-id>"
}

For realtime WebSocket requests, the connection upgrades first. The server then emits the same structured authentication error as a WebSocket error event and closes the connection. Realtime STT closes with code 1000 and incremental-input TTS closes with code 1008, so classify the failure using error.code rather than the close code.

Replace or update the key rather than retrying the same credential in a loop.