SoxAIDocs
API Reference

Authentication

How to authenticate with the SoxAI API using Bearer tokens

Authentication

SoxAI uses API tokens for authentication. Tokens are created in the Console and must be included in every API request.

Bearer Token

Include your token in the Authorization header:

Authorization: Bearer sox-your-token-here

All tokens start with the sox- prefix.

Creating a Token

  1. Log in to console.soxai.io
  2. Navigate to Settings → API Tokens
  3. Click Create Token
  4. Set a name and configure optional restrictions
  5. Copy the token immediately — it is only shown once

Token Scopes and Restrictions

When creating a token you can configure:

SettingDescription
NameHuman-readable label for identification in logs
Model allowlistRestrict to specific models (empty = all models allowed)
Spending limitMaximum USD this token can spend per day
IP allowlistCIDR ranges from which requests are accepted
ExpiryOptional expiration date

Revoking a Token

To revoke a token, go to Settings → API Tokens, find the token, and click Revoke. Revocation takes effect immediately — in-flight requests using the token will receive a 401 response.

Security Best Practices

Never commit tokens to version control. Use environment variables:

# .env.local (add to .gitignore)
SOXAI_API_KEY=sox-your-token-here

Use the most restricted token for each application. A token used by a customer-facing app does not need admin-level access.

Rotate tokens periodically. Create a new token before revoking the old one to avoid downtime.

Set IP allowlists for server-side tokens. This prevents a leaked token from being used outside your infrastructure.

Token vs. User Session

API tokens are separate from user login sessions. The Console uses a session cookie for the web interface. Your API tokens are for programmatic access to the gateway endpoint only.