# API keys

> Create a key for each tool, cap its spend, and disable keys you no longer use.

Open [API keys](https://deference.si/keys) to create and manage the keys that authenticate requests. Give each tool its own key so you can track its spend and disable it separately.

## Create and save a key

1. Select **Create key**, or press C.
2. Enter a name of up to 40 characters. Use the tool or job's name.
3. Optionally set a credit limit in dollars and an expiry of 7, 30 or 90 days. Choose Never for no expiry.
4. Select **Copy key** in the confirmation, save it where your tool reads credentials, then select **Done**.

The full key appears only once. Deference stores its hash and a few characters for recognition. If you lose it, create a replacement.

Your first key completes a step toward [free credit](https://deference.si/docs/concepts/free-credit). Grants need a verified email or Google account.

## Check a key's spend

The list shows each key's masked value, spend against its limit, last use and creation date. Disabled keys and expiry dates appear in the status column. Keys created through the [MCP server](https://deference.si/docs/coding-tools/mcp) carry an Agent label.

A credit limit is the total the key can spend. Running requests also reserve part of it. Use **Edit limit** in the row menu to change or remove the limit. If you lower it below what the key already spent, new requests return `402 key_limit_reached`.

## Disable or replace a key

Choose **Disable** in the row menu to stop new requests immediately. You can undo the action or choose **Enable** later. An expired key needs a replacement.

To rotate a key, create its replacement, update your tool, and confirm a request under the new key in [Activity](https://deference.si/activity). Then disable the old key. See [Keys and security](https://deference.si/docs/dashboard/keys-and-security).

Delete is available for disabled and expired keys. Confirm the named key before deleting it. Deletion cannot be undone, and past requests keep the key's name.

## Set up a client

The **Connect** section has both base URLs with copy buttons: `https://deference.si/v1` for OpenAI-style clients and `https://deference.si` for Anthropic-style clients. Choose a guide under **Set up a tool** for the exact settings your client needs.
