Tenzro LabsPlatform

API keys & permissions

Every surface authenticates the same way: a Tenzro Labs API key sent as a bearer token. The key is the primary identifier — it names the party calling, you or one of your agents, and everything else follows from it.

http
Authorization: Bearer tzl_...

Create and revoke keys on the API keys page, or with the Platform API and MCP server using a key that has manage. The secret is shown once; only a hash is stored. Revocation takes effect on the next request.

Party — who a key identifies

Key issued toIdentityNotes
Youdid:tenzro:human:…Rooted in your passkeys. Can hold any permission.
An agentdid:tenzro:machine:…Inference only. Usage counts against the agent's limits and appears as the agent. See Identity & agents.

Permissions — what a key can do

PermissionGrants
inferenceCall models through the Inference API, billed to the account's credit.
readView the account through the Platform API and MCP: balance, activity, orders, keys, plans, rentals, tickets.
manageCreate orders and start payment, create and revoke keys, redeem tickets, cancel or resume plans. Implies read in the UI.

New keys default to inference only. A key can only create keys with permissions it holds itself.

A manage key cannot move money on its own: paying an order returns a Stripe Checkout link or a stablecoin deposit address that a person completes. It can still spend existing credit by minting inference keys, so store it like a password.

Access — where inference can go

AccessBehaviour
All machines (default)Requests route across every healthy machine serving the model. Uses machine-pinned credit for the serving machine first, then credit usable anywhere.
One machineRequests only go to that machine. Useful for data residency or consistent latency.
PlanPinned to the plan's machine, subject to the plan's rate limit and model list; draws from the plan's included credit first. No machine offers plans on testnet.
RentalAuthenticates against a rented slice for the rental's term. Usage is prepaid. No machine offers rentals on testnet.

Authentication errors

StatusCodeMeaning
401unauthenticatedNo key was sent to an endpoint that needs one.
401invalid_keyThe key is malformed, unknown, or revoked.
403forbiddenThe key lacks the permission this operation needs.
shell
curl https://platform.tenzro.xyz/api/me -H "Authorization: Bearer $TENZRO_API_KEY"

{"error": {"code": "forbidden", "message": "This key lacks the \"read\" permission. ..."}}

Good practice

  • Use separate keys per app and environment so one can be revoked without touching the others.
  • Give production services inference only; keep manage keys for automation you control.
  • Pin keys to a machine when the workload must stay in one region.
  • Check last_used_at on the keys list and revoke keys that are no longer used.