SN API Key Quickstart
This is the tested path for an isa_model deployment in the SN cluster. It uses the SN Console and the SN gateway—not isagent.io.
1. Open the SN Console
Sign in, then open:
https://aix.prod.sn.local/console/dashboard/developer/api-keys
Choose Create new key and configure the controls deliberately:
| Control | Guidance |
|---|---|
| Name | Use a purpose and environment, for example support-router-staging. |
| Project scope | Leave blank for an organization-wide key, or enter the exact project UUID shown in Console (legacy proj_... IDs are also accepted). |
| Owner type | Use Organization for an interactive/shared integration or Service account for a workload. |
| Service account ID | Required when the owner is a service account. |
| Scopes | Select inference:invoke; add model:read only when the workload must list models. |
| Expiry | Prefer a short expiry for tests and rotate long-lived workload credentials. |
| IP allowlist | Optional IP/CIDR restriction. Use the client address seen by the trusted SN gateway. |
| Requests per minute | Optional per-key request ceiling. |
| Spend limit | Optional USD ceiling for this key. |
The one-time secret is shown only after creation. SN keys currently use the shared isa_ prefix; the edition does not change it to sn_.
2. Handle the secret safely
Do not put the key in source code, screenshots, tickets, shell history, or documentation. Paste it into a silent shell prompt:
read -s ISA_API_KEY
export ISA_API_KEY
echoStore production credentials in your approved secret manager. The examples below contain no real key.
3. Make the tested inference request
The SN gateway exposes the Model API at https://aix.prod.sn.local/api/v1. The following request uses the model verified in the SN cluster:
curl --fail-with-body \
https://aix.prod.sn.local/api/v1/chat/completions \
-H "Authorization: Bearer ${ISA_API_KEY}" \
-H "Content-Type: application/json" \
-d '{
"model": "qwen3.6-27b",
"provider": "isa",
"messages": [
{"role": "user", "content": "Reply with exactly: SN_API_KEY_OK"}
],
"temperature": 0,
"max_tokens": 32
}'A successful response has a choices[0].message.content value and a usage object. The provider may return surrounding reasoning depending on the model, so validate the response structurally rather than logging the secret.
Project-scoped keys
If you selected a project while creating the key, the project is stored with the key. Send only the key: the SN gateway validates it and injects the stored project as trusted upstream identity.
curl --fail-with-body \
https://aix.prod.sn.local/api/v1/chat/completions \
-H "Authorization: Bearer ${ISA_API_KEY}" \
-H "Content-Type: application/json" \
-d '{
"model": "qwen3.6-27b",
"provider": "isa",
"messages": [{"role": "user", "content": "Hello from this project"}],
"max_tokens": 32
}'Do not send project or organization identity headers. The gateway strips caller-supplied identity and derives project attribution from the verified key.
4. Verify the selected controls
Before handing the key to a workload, test the controls you selected:
- Remove
inference:invokeon a disposable key and confirm inference returns403. - For a project-scoped key, confirm usage is attributed to the project selected when the key was created.
- Test the IP allowlist from an allowed and a disallowed client path.
- Send one more request than the configured requests per minute and confirm
429plusRetry-After. - Use a small disposable spend limit and confirm exhaustion returns
402without provider dispatch. - Confirm Last used changes in the Console after a successful request.
Common responses are 401 for an invalid, expired, or revoked key; 403 for scope, project, or IP denial; 402 for an exhausted spend limit; 429 for a request limit; and 503 when a required enforcement backend is unavailable.
5. Revoke the temporary key
After validation, return to the API-key inventory, find the temporary key, choose Revoke, and confirm the prompt. Revocation is destructive and cannot be undone. Repeat the inference request and confirm it now returns 401.
Finally, remove the secret from the current shell:
unset ISA_API_KEYCreate a separate least-privilege key for the real workload; never reuse the temporary test key.