Skip to content

Sign-in, accounts and API keys

  • An administrator creates each account, one at a time or by importing a CSV file.
  • The new user gets a one-time setup link (valid for 48 hours by default) and sets their own password.
  • Passwords must be at least 12 characters, and very common passwords are refused.
  • After 10 wrong attempts, sign-in is paused for 15 minutes for that email.
  • If you don’t use ZenithAI for 12 hours, you are signed out. Your administrator can change this.

Programs and scripts use an API key. A key belongs to one person and works with that person’s access.

  1. Sign in to the web app and open Settings › API keys.
  2. Click Create key and give it a clear name, such as excel-macro or billing-bot.
  3. Copy the key. It is shown only once.

Good to know:

  • Up to 20 keys per person.
  • The server keeps keys only in scrambled (hashed) form. Nobody, not even an administrator, can read one back.
  • The keys page shows when each key was last used and from which address.
  • A key stops working while its owner’s account is suspended or archived.
  • An API key can’t create or delete other keys. That always needs a signed-in person.
Part of the API Header
/v1/models, /v1/chat/completions Authorization: Bearer <API_KEY>
/chat, /generate, /pdf, /ocr and file downloads Authorization: Bearer <API_KEY> or X-API-Key: <API_KEY>

Send the header on file downloads and status checks too. Never put a key in a URL.

Common questions

How do new people get a ZenithAI account?

An administrator creates the account, one at a time or from a CSV file, and shares a one-time setup link. The person opens the link, sets a password of at least 12 characters, and can then sign in.

How many API keys can I have?

Up to 20 keys per person. Create and delete them in the web app under Settings, then API keys. A key stops working while its owner's account is suspended.

Can my program sign in with my password instead of a key?

Use an API key for programs. Keys can be deleted one at a time without changing your password, and they are stored on the server only in scrambled form, so nobody can read them back.