---
title: Check your key
description: The one live operation on this site: paste a key, and the platform reads back what it is and what it may do.
keywords: key check, verify, identity, echo, 401
group: get-started
---

## What it does {#what-it-does keywords="identity, echo, verify, live"}

Every model call through the gateway is authenticated by this same API key. The identity echo is the one that answers **about** the key instead of with a model's output: it reads the presenting key's own record back to you. That is exactly why it belongs on the documentation site — it is the shortest honest answer to "does my key work", and it is the one live tool this site runs for itself.

What comes back is the key's own record — the name you gave it, the masked prefix and tail that identify it, what funds it, when it expires if it ever does, the scope it may reach and the version it is on. The secret is not in that answer. One operation does carry it — the call that mints the key answers with it once, which is the only time it is ever shown — and nothing afterwards reads it back.

The key you type lives in one place — the field below — and leaves this page only as the bearer header of that one request. It is never written to storage, to a cookie, to the address bar or to a log, and it is dropped from the page the moment the answer arrives, whether the answer is yes or no. A second check is a second paste.

A refused key gets one sentence and not four. The platform answers an unknown, a revoked, an expired and a malformed key with the same status on purpose: telling them apart would turn the surface into an oracle over key material.

## Run it {#run-it keywords="paste, check, live"}

:::tip
Paste the key here and nowhere else. No other page of this documentation asks for a key, and a real key does not belong in an example, in a chat, or in an issue tracker.
:::

:::slot key-check
:::

## What next {#next keywords="next, header, errors, keys"}

:::cards
- [Authentication](/en/authentication) — the header that carries the key, and what the key may reach.
- [Errors](/en/errors) — what every status the gateway answers with means.
- [Quickstart](/en/quickstart) — the first call with this key.
- [Models](/en/models) — which identifiers a request may name.
:::
