Skip to main content
API Usage

Obtain an API key

Before you use models or applications in Alibaba Cloud Model Studio, you must obtain an API key for authentication.

This topic describes the pay-as-you-go API key for Model Studio. If you are using a Token Plan or Coding Plan, use the corresponding dedicated API key (starts with sk-sp-). For more information, see Token Plan API Key and Coding Plan API Key.

Create an API key

This procedure must be performed by an Alibaba Cloud account or a RAM user with administrator or API-Key page permissions.
  • China (Beijing), Singapore, and other regions
  • US (Virginia) region
  1. Go to the Alibaba Cloud Model Studio console. In the upper-right corner, select a region, such as China (Beijing), Singapore, Japan (Tokyo), China (Hong Kong), or Germany (Frankfurt). Go to the API Key page and click Create API Key.
  2. In the dialog box, configure the following settings, and then click OK.
    • Workspace: We recommend that you select the default workspace.
    • Description (optional, up to 200 characters): Enter a description to help you identify the purpose of the API key.
    • Permissions: We recommend that you select All. For more granular control, select Custom to configure accessible IP addresses and models.

    How do I choose permission settings for an API key?

    Alibaba Cloud Model Studio provides two types of permission settings. Select one based on your business requirements:
    • All: Grants the API key permission to call any model or application.
    • Custom: Allows you to configure an IP address whitelist and an accessible model scope.
      By default, all IPv4 (0.0.0.0/0) traffic is allowed. Support for IPv6 is available only in the China (Beijing) region.
      You can add up to 20 IPv4 or IPv6 addresses or CIDR blocks to the IP address whitelist.
    In the Custom permission settings, when the Access Scope toggle is enabled, you can select the models that the API key is allowed to call from the model list (for example, Qwen3.7-Plus and Qwen3.7-Max). The number of selected permission points is displayed on the right. After configuration, click OK.
  3. After the key is created, the complete API key and API Host (service endpoint address) are displayed in a dialog box. You must copy or download and save them immediately. Keep them confidential. Anyone with your API key can make service requests on your behalf, which may incur charges. After you close the dialog box, you cannot view or copy the plaintext API key again. If the key is lost, reset it or create a new one.
    An Alibaba Cloud account can view the API keys in all workspaces. A RAM user can view only the API keys in the workspaces that they have joined.

API key management operations

In the API key list, you can perform the following operations on existing API keys:
  • Edit: Modify the description and permission settings of the API key.
  • Delete: Permanently delete the API key. This operation cannot be undone.
  • Disable (not supported in the US (Virginia) region): Suspend the API key without deleting it. You can re-enable it at any time.
  • Reset (not supported in the US (Virginia) region): Generate a new key value. The old key becomes invalid immediately.
If you require team collaboration or cost allocation, consider the following:
  • Workspace: A workspace is used to isolate resources and permissions for different projects or teams. To control which models a user group can call or to allocate costs for model calls, create or select a sub-workspace from the list.
For more information, see API key permissions and Query bills and manage costs.

Configure API key as an environment variable

We recommend setting your API key as an environment variable. This helps you avoid hard-coding the key in your source code, reducing the risk of accidental exposure.
  • Linux
  • macOS
  • Windows
  • Permanent
  • Temporary
To make the API key available in all new sessions for the current user, set it as a permanent environment variable.
  1. Run the following command to append the environment variable setting to the ~/.bashrc file.
# Replace YOUR_DASHSCOPE_API_KEY with your DashScope API key
echo "export DASHSCOPE_API_KEY='YOUR_DASHSCOPE_API_KEY'" >> ~/.bashrc
Alternatively, you can manually edit the ~/.bashrc file.
Run the following command to open the ~/.bashrc file.
nano ~/.bashrc
Add the following content to the configuration file.
# Replace YOUR_DASHSCOPE_API_KEY with your DashScope API key
export DASHSCOPE_API_KEY="YOUR_DASHSCOPE_API_KEY"
In the nano editor, press Ctrl+X, then Y, and then Enter to save and close the file.
  1. Run the following command to apply the changes.
source ~/.bashrc
  1. Open a new terminal window and run the following command to verify that the environment variable is set.
echo $DASHSCOPE_API_KEY

Use an API key

When you call a model from code or a third-party tool, in addition to the API key you must specify a service endpoint (the API Host shown in the creation success dialog, which corresponds to the base_url in your SDK or HTTP request). Model Studio provides both OpenAI-compatible and Anthropic-compatible protocol interfaces. The base_url differs between the two protocols and varies by region. Refer to the documentation for the protocol you use:
Do not expose your API key.

API key security upgrade

Model Studio has upgraded the pay-as-you-go API key generation and storage mechanism for enhanced security (except for the US (Virginia) region). API keys created before the upgrade that start with sk- remain fully functional and are not affected. All API keys created after the upgrade start with sk-ws. The following table describes the main differences between API keys created before and after the upgrade.

Comparison item

Pre-upgrade keys

Post-upgrade keys

Key format

Starts with sk- and is about 32 characters long.

Starts with sk-ws and is longer than the previous format.

Plaintext viewing

You can copy the complete plaintext key from the console at any time.

The plaintext key is displayed only once upon creation. It cannot be viewed again after the dialog box is closed. If lost, reset or create a new key.

Calling capability

Can be used to call models normally; functionality is unaffected.

Can be used to call models normally; functionality is identical to pre-upgrade keys.

Recommended action

We recommend that you create a new key to replace the old one for improved security.

Copy and save the key immediately after creation, and store it securely.

Manage API keys through the API

In addition to console operations, Alibaba Cloud Model Studio provides OpenAPI operations that let you create, query, edit, delete, enable, disable, and reset API keys programmatically, so that you can integrate API key management into automated workflows.
Calling the following operations requires signature authentication with your Alibaba Cloud account AccessKey (not the API key itself) and the corresponding RAM permissions. You can debug each operation online in the OpenAPI developer portal, or call it through an Alibaba Cloud SDK.

Operation

Description

CreateApiKey

Creates an API key.

GetApiKey

Queries the information of a specified API key.

ListApiKeys

Queries the list of API keys.

UpdateApiKey

Edits an API key, such as its description and permission configuration.

DeleteApiKey

Deletes an API key. This operation cannot be undone.

EnableApiKey

Enables an API key (not supported in the US (Virginia) region).

DisableApiKey

Disables an API key. The key is retained and can be re-enabled at any time (not supported in the US (Virginia) region).

ResetApiKey

Resets an API key. A new key value is generated and the old key immediately becomes invalid (not supported in the US (Virginia) region).

API key permissions

An API key's permissions are determined entirely by its workspace. All API keys within the same workspace have identical permissions. You do not need to create different API keys for different models, such as text-to-text, text-to-image, or speech synthesis models.
  • API key in the default workspace: Can call all standard models and any application within the default workspace.
  • API key in a sub-workspace: Can call standard models authorized for the sub-workspace and any application within that sub-workspace.
When you Create API Key or click Edit for an existing API key, you can switch the Permissions to Custom and configure the following:
  • IP address whitelist: Allows only IP addresses on the whitelist to use the API key to make calls (supports IPv4 addresses and CIDR blocks; IPv6 is supported only in the China (Beijing) region, and the US (Virginia) region supports IPv4 only).
  • Access Scope: Select the specific models or applications that this API key can access. The key cannot call unselected resources.

API key validity

API keys do not expire. They remain valid until you manually delete them. To grant temporary access to third-party applications or users, or to strictly control high-risk operations such as accessing or deleting sensitive data, you can generate a temporary API key (valid for 60 seconds). This avoids exposing a long-term API key and reduces the risk of leaks.

Error codes

If a model call fails and returns an error message, see Error codes for troubleshooting.

FAQ

Q: How many API keys can I create under a single Alibaba Cloud account? A: For the Singapore, China (Beijing), China (Hong Kong), Japan (Tokyo), and Germany (Frankfurt) regions, each Alibaba Cloud account can create up to 50 API keys per region. For the US (Virginia) region, each owner account, including the Alibaba Cloud account, can create up to 20 API keys. Q: Are API keys created by a RAM user still valid after the user is deleted? A: No. After you disable or delete a RAM user in the RAM console, all API keys created by that user become invalid and can no longer be used for model calls. Q: I used theechocommand and confirmed the environment variable was set correctly. Why does my code still report that the API key cannot be found? A: This can occur for the following reasons:
  • Scenario 1: A temporary environment variable was set. A temporary variable is valid only within the current terminal session and does not affect running IDEs or other applications. Refer to the instructions in this topic to set a permanent environment variable.
  • Scenario 2: The IDE, command-line tool, or application was not restarted.
    • You must restart your IDE (such as VS Code) or terminal to load the new environment variables.
    • If you set the environment variable after deploying an application, you must restart the application service to reload the environment variables.
  • Scenario 3: The variable is missing from a service configuration file. If your application is started by a service manager, such as systemd or supervisord, you may need to add the environment variable to the service manager's configuration file.
  • Scenario 4: Using thesudocommand. If you use sudo python xx.py to run the script, the environment variables of the current user may not be inherited. This is because sudo does not inherit all environment variables by default. You can use the sudo -E python xx.py command, where the -E parameter ensures that the environment variables are passed. If you have permission to run the script, you can run python xx.py directly.