Authentication
How to authenticate with the SoxAI API using Bearer tokens
Authentication
SoxAI uses API tokens for authentication. Tokens are created in the Console and must be included in every API request.
Bearer Token
Include your token in the Authorization header:
Authorization: Bearer sox-your-token-hereAll tokens start with the sox- prefix.
Creating a Token
- Log in to console.soxai.io
- Navigate to Settings → API Tokens
- Click Create Token
- Set a name and configure optional restrictions
- Copy the token immediately — it is only shown once
Token Scopes and Restrictions
When creating a token you can configure:
| Setting | Description |
|---|---|
| Name | Human-readable label for identification in logs |
| Model allowlist | Restrict to specific models (empty = all models allowed) |
| Spending limit | Maximum USD this token can spend per day |
| IP allowlist | CIDR ranges from which requests are accepted |
| Expiry | Optional expiration date |
Revoking a Token
To revoke a token, go to Settings → API Tokens, find the token, and click Revoke. Revocation takes effect immediately — in-flight requests using the token will receive a 401 response.
Security Best Practices
Never commit tokens to version control. Use environment variables:
# .env.local (add to .gitignore)
SOXAI_API_KEY=sox-your-token-hereUse the most restricted token for each application. A token used by a customer-facing app does not need admin-level access.
Rotate tokens periodically. Create a new token before revoking the old one to avoid downtime.
Set IP allowlists for server-side tokens. This prevents a leaked token from being used outside your infrastructure.
Token vs. User Session
API tokens are separate from user login sessions. The Console uses a session cookie for the web interface. Your API tokens are for programmatic access to the gateway endpoint only.