Authorizing an app
What you see, and what you agree to, when a third-party app asks for a key on your account.
Some apps built on ai.ml let you bring your own account: the app sends you to the console, you approve, and the app receives an API key that spends your credits. This page describes that approval screen, titled Authorize an app, and what each choice does.
You reach the screen only by following a link from the app. You must be signed in, and the key is created on the organization you have selected in the console.
What the screen shows
- The app's name, logo and category, as its developer registered them.
- A sentence naming the app and your organization: the app wants to create an API key on your account, and you will pay for its usage.
- Scopes: what the key will be allowed to do. An app can ask only for model access and read access. It cannot get a key that manages your organization, keys or credits.
- The spend cap: either Hard spend cap with an amount per day, or No spend cap set by the app.
- A reminder that you can revoke the key at any time from API keys.
Check that the app and the organization are the ones you expect before you continue. If the app set no spend cap, the key can spend up to your balance, within your project's budget if it has one.
Authorize
Press Authorize to approve. One of two things happens:
- You are sent back to the app, which finishes on its own.
- The screen shows a one-time code. Copy it into the app to finish. The code expires in 5 minutes and works once.
The app then holds an ordinary API key on your organization:
- its traffic is attributed to the app, so you can see what it spent in your usage;
- a spend cap, if the app set one, is a hard daily budget on the key. Once it is reached, the app's requests are refused until the next day;
- it appears with your other keys under API keys.
Creating a key needs the owner, admin or member role. With another role, approving fails with an error.
Deny
Press Deny to refuse. No key is created. You are sent back to the app, which is told you declined, or the screen says You declined the request.
Change your mind later
Open API keys, find the app's key, and revoke it. The app stops working with your account immediately. On the key's page you can also lower or raise its budget.
If the link is broken
If the screen says the authorization link is missing client_id or code_challenge, the app sent an incomplete link. Go back to the app and start again, or contact its developer.