Sign-in, accounts and API keys
How people sign in
Section titled “How people sign in”- An administrator creates each account, one at a time or by importing a CSV file.
- The new user gets a one-time setup link (valid for 48 hours by default) and sets their own password.
- Passwords must be at least 12 characters, and very common passwords are refused.
- After 10 wrong attempts, sign-in is paused for 15 minutes for that email.
- If you don’t use ZenithAI for 12 hours, you are signed out. Your administrator can change this.
API keys for programs
Section titled “API keys for programs”Programs and scripts use an API key. A key belongs to one person and works with that person’s access.
- Sign in to the web app and open Settings › API keys.
- Click Create key and give it a clear name, such as excel-macro or billing-bot.
- Copy the key. It is shown only once.
Good to know:
- Up to 20 keys per person.
- The server keeps keys only in scrambled (hashed) form. Nobody, not even an administrator, can read one back.
- The keys page shows when each key was last used and from which address.
- A key stops working while its owner’s account is suspended or archived.
- An API key can’t create or delete other keys. That always needs a signed-in person.
Which header to send
Section titled “Which header to send”| Part of the API | Header |
|---|---|
/v1/models, /v1/chat/completions |
Authorization: Bearer <API_KEY> |
/chat, /generate, /pdf, /ocr and file downloads |
Authorization: Bearer <API_KEY> or X-API-Key: <API_KEY> |
Send the header on file downloads and status checks too. Never put a key in a URL.
Common questions
How do new people get a ZenithAI account?
An administrator creates the account, one at a time or from a CSV file, and shares a one-time setup link. The person opens the link, sets a password of at least 12 characters, and can then sign in.
How many API keys can I have?
Up to 20 keys per person. Create and delete them in the web app under Settings, then API keys. A key stops working while its owner's account is suspended.
Can my program sign in with my password instead of a key?
Use an API key for programs. Keys can be deleted one at a time without changing your password, and they are stored on the server only in scrambled form, so nobody can read them back.