Getting Started

Authentication

The Cortiqa API uses API keys for authentication. Every request must include a valid API key in the request headers.


API Keys

API keys are generated from the Cortiqa Console. Each key is cryptographically signed (prefixed with sk-cortiqa-) and tracks your rate limits and credit balance.

Using Your API Key

Pass your secret key in the standard Authorization: Bearer header (or alternatively x-api-key):

Terminal
curl https://api.cortiqa.co/api/v1/chat/completions   -H "Authorization: Bearer sk-cortiqa-YOUR_API_KEY"   -H "Content-Type: application/json"   -d '{
    "model": "openai/gpt-oss-120b",
    "messages": [
      {"role": "user", "content": "Hello, Cortiqa!"}
    ]
  }'

Or using the official Python SDK:

auth.py
from cortiqa import Cortiqa

# Option 1: Reads CORTIQA_API_KEY environment variable automatically
client = Cortiqa()

# Option 2: Pass key explicitly
client = Cortiqa(api_key="sk-cortiqa-YOUR_API_KEY")

Environment Variables

The recommended approach is to store your API key in an environment variable:

.env
# Linux/macOS
export CORTIQA_API_KEY="sk-cortiqa-your-api-key-here"

# Windows (PowerShell)
$env:CORTIQA_API_KEY="sk-cortiqa-your-api-key-here"

# .env file (use with dotenv)
CORTIQA_API_KEY="sk-cortiqa-your-api-key-here"

Security Best Practices

Never expose your API key
API keys grant full access to your account. Treat them like passwords.
  • Never commit keys to version control. Add .env to your .gitignore.
  • Never use keys in client-side code. Always make API calls from a backend server.
  • Rotate keys regularly. Generate new keys periodically and revoke old ones.
  • Use the principle of least privilege. Create separate keys for different environments.
  • Monitor usage. Set up alerts for unusual API usage patterns.

Key Management

You can manage your API keys from the Cortiqa Console:

  • Create new keys with descriptive names
  • Revoke compromised or unused keys immediately
  • Set permissions to restrict key access to specific models or endpoints
  • View usage for each key to track consumption
Organization keys
If you are part of an organization, your admin can create organization-level API keys that are shared across team members with configurable permissions.
Was this page helpful?