# API keys & model groups

Give each application the access it needs.

<a id="create"></a>

## Create a site key

Create a key in the matching model group in the console. Keep it on your server or in local environment variables, outside public web bundles.

- [Manage API keys](https://api.ohgrok.com/keys)

<a id="groups"></a>

## Match the model group

The group attached to the key controls routing and price. A default-group key is not automatically valid for dedicated channel groups. Select the group shown on the model detail page.

- Text example: grok-4.5, channel2-grok-cursor.
- Image example: image-2, its enabled image-generation group.
- Video example: seedance-2.0-fast, its corresponding Seedance group.

<a id="header"></a>

## Authentication

Send the site key in the Authorization header. Do not use your console session cookie or an upstream provider key.

```
Authorization: Bearer YOUR_API_KEY
```

<a id="storage"></a>

## Store and rotate

Use server-side environment variables. Exclude local secret files from version control. If a key is exposed, revoke it in the console, create a replacement and update your application.

