Skip to Content

SN API Key Quickstart

This is the tested path for an isa_model deployment in the SN cluster. It uses the SN Console and the SN gateway—not isagent.io.

1. Open the SN Console

Sign in, then open:

https://aix.prod.sn.local/console/dashboard/developer/api-keys

Choose Create new key and configure the controls deliberately:

ControlGuidance
NameUse a purpose and environment, for example support-router-staging.
Project scopeLeave blank for an organization-wide key, or enter the exact project UUID shown in Console (legacy proj_... IDs are also accepted).
Owner typeUse Organization for an interactive/shared integration or Service account for a workload.
Service account IDRequired when the owner is a service account.
ScopesSelect inference:invoke; add model:read only when the workload must list models.
ExpiryPrefer a short expiry for tests and rotate long-lived workload credentials.
IP allowlistOptional IP/CIDR restriction. Use the client address seen by the trusted SN gateway.
Requests per minuteOptional per-key request ceiling.
Spend limitOptional USD ceiling for this key.

The one-time secret is shown only after creation. SN keys currently use the shared isa_ prefix; the edition does not change it to sn_.

2. Handle the secret safely

Do not put the key in source code, screenshots, tickets, shell history, or documentation. Paste it into a silent shell prompt:

read -s ISA_API_KEY export ISA_API_KEY echo

Store production credentials in your approved secret manager. The examples below contain no real key.

3. Make the tested inference request

The SN gateway exposes the Model API at https://aix.prod.sn.local/api/v1. The following request uses the model verified in the SN cluster:

curl --fail-with-body \ https://aix.prod.sn.local/api/v1/chat/completions \ -H "Authorization: Bearer ${ISA_API_KEY}" \ -H "Content-Type: application/json" \ -d '{ "model": "qwen3.6-27b", "provider": "isa", "messages": [ {"role": "user", "content": "Reply with exactly: SN_API_KEY_OK"} ], "temperature": 0, "max_tokens": 32 }'

A successful response has a choices[0].message.content value and a usage object. The provider may return surrounding reasoning depending on the model, so validate the response structurally rather than logging the secret.

Project-scoped keys

If you selected a project while creating the key, the project is stored with the key. Send only the key: the SN gateway validates it and injects the stored project as trusted upstream identity.

curl --fail-with-body \ https://aix.prod.sn.local/api/v1/chat/completions \ -H "Authorization: Bearer ${ISA_API_KEY}" \ -H "Content-Type: application/json" \ -d '{ "model": "qwen3.6-27b", "provider": "isa", "messages": [{"role": "user", "content": "Hello from this project"}], "max_tokens": 32 }'

Do not send project or organization identity headers. The gateway strips caller-supplied identity and derives project attribution from the verified key.

4. Verify the selected controls

Before handing the key to a workload, test the controls you selected:

  • Remove inference:invoke on a disposable key and confirm inference returns 403.
  • For a project-scoped key, confirm usage is attributed to the project selected when the key was created.
  • Test the IP allowlist from an allowed and a disallowed client path.
  • Send one more request than the configured requests per minute and confirm 429 plus Retry-After.
  • Use a small disposable spend limit and confirm exhaustion returns 402 without provider dispatch.
  • Confirm Last used changes in the Console after a successful request.

Common responses are 401 for an invalid, expired, or revoked key; 403 for scope, project, or IP denial; 402 for an exhausted spend limit; 429 for a request limit; and 503 when a required enforcement backend is unavailable.

5. Revoke the temporary key

After validation, return to the API-key inventory, find the temporary key, choose Revoke, and confirm the prompt. Revocation is destructive and cannot be undone. Repeat the inference request and confirm it now returns 401.

Finally, remove the secret from the current shell:

unset ISA_API_KEY

Create a separate least-privilege key for the real workload; never reuse the temporary test key.