Skip to main content
The cloro API uses Bearer token authentication. Create and manage your keys in the dashboard.

Using your API key

The Bearer token in the Authorization header is your API key — there’s no separate token exchange or OAuth flow. Copy the key from the dashboard and pass it directly with the Bearer prefix on every request:
Never expose your API key in client-side code or public repositories, and never share it with unauthorized users. Keep it in a secrets manager or an environment variable, not your source tree.
Each provider has its own endpoint — /v1/monitor/chatgpt, /v1/monitor/google, and so on. There is no single /v1/monitor path and no model field in the request body. See Providers for the full list.

Authentication errors

If authentication fails, you’ll receive a 401 Unauthorized response:
Common causes:
  • Missing Bearer prefix: include Bearer before your API key
  • Invalid API key: check that you’re using the correct key
  • Expired API key: some API keys have expiration dates
  • Rate limit exceeded: you’ve exceeded your plan’s rate limit

Environment variables

API key management

Naming a key

When you create a key, the Create API key dialog accepts an optional human-readable name (up to 64 characters). Use it to tell keys apart in the API keys table, for example production, staging, or ricardo-laptop. Leave the field empty to create an unnamed key, matching how keys behaved before names were supported. The name is a label only and is not part of the credential, so renaming or omitting it does not change how the key authenticates.

The key is shown once

The full key appears only in the dialog that opens when you create it. Copy it there and store it in a secrets manager or an environment variable. Afterwards the API keys table shows the prefix (and the name, if you set one) only, and support cannot recover the key because cloro does not store it in readable form. If you lose a key, create a new one and invalidate the old one. There is no rotate action, and invalidation is immediate, so any integration still on the old key starts failing with 401 Unauthorized.
If Copy to clipboard reports “Unable to copy API key”, your browser refused clipboard access. Select the key in the field and copy it manually before closing the dialog.

Compromised keys

If you suspect a key has been compromised, revoke it and generate a new one in the dashboard. You can also create multiple keys for different purposes: one for your live application, one for local development and testing, one for automated testing and deployment pipelines, and individual keys for team members. cloro does not use a formal test-key vs. live-key split (there are no test_/live_ prefixes and no separate sandbox environment). Every key hits the same production API and draws from the same organization credit balance. Isolate environments by generating a distinct key per environment and revoking any one of them independently when needed.

Need help?

  • Check our API Reference
  • Get help: paid plans via the in-dashboard support widget, free tier via the Ask Assistant button in these docs