> ## Documentation Index
> Fetch the complete documentation index at: https://docs.acasia.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an API key

> Generate a credential for programmatic access, and store it where it will not leak.

## Prerequisites

* An Acasia account with access to an organization
* Organization Admin role or Member role with appropriate access

## Steps

<Steps>
  <Step title="Navigate to API Keys">
    In the Developer Portal, click **API Keys** in the left navigation sidebar.
  </Step>

  <Step title="Click Create API Key">
    The key creation panel opens.
  </Step>

  <Step title="Name the key">
    Enter a descriptive name that identifies the application, environment, or owner. Examples: `production-app`, `dev-pipeline`, `data-team`, `ci-workflow`.
  </Step>

  <Step title="Copy the key immediately">
    After creation, the full key value is displayed **once**. Copy it now and store it in your secrets manager. It cannot be retrieved again — if lost, revoke and create a new one.
  </Step>
</Steps>

## Storing the key

Store API keys in a secrets manager or environment variable system:

* **AWS Secrets Manager** — for cloud-hosted applications
* **GitHub Actions secrets** — for CI/CD workflows
* **HashiCorp Vault** — for infrastructure-managed secrets
* **`.env` file** — for local development only; never commit to source control

```bash theme={null}
# .env (local development only)
ACASIA_API_KEY=your-key-here
ACASIA_ENDPOINT_URL=https://your-endpoint-url
```

<Warning>
  Never commit API keys to source code. If a key is exposed, revoke it immediately and create a new one.
</Warning>

## Using the key

```typescript theme={null}
const response = await fetch(process.env.ACASIA_ENDPOINT_URL, {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.ACASIA_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    model: process.env.ACASIA_MODEL_NAME,
    messages: [{ role: "user", content: prompt }],
  }),
});
```

## Checklist

* Key is named by application, environment, or owner
* Key value was copied at creation time
* Key is stored in a secrets manager — not in source code
* Application is reading the key from the environment at runtime

## Next steps

* [Deploy your first inference endpoint](/get-started/deploy-inference-endpoint)
* [API Keys reference](/developer-portal/api-keys)
