Before you use models or applications in Alibaba Cloud Model Studio, you must obtain an API key for authentication.
sk-sp-). For more information, see Token Plan API Key and Coding Plan API Key.Create an API key
- China (Beijing), Singapore, and other regions
- US (Virginia) region
- Go to the Alibaba Cloud Model Studio console. In the upper-right corner, select a region, such as China (Beijing), Singapore, Japan (Tokyo), China (Hong Kong), or Germany (Frankfurt). Go to the API Key page and click Create API Key.
-
In the dialog box, configure the following settings, and then click OK.
- Workspace: We recommend that you select the default workspace.
- Description (optional, up to 200 characters): Enter a description to help you identify the purpose of the API key.
- Permissions: We recommend that you select All. For more granular control, select Custom to configure accessible IP addresses and models.
How do I choose permission settings for an API key?
Alibaba Cloud Model Studio provides two types of permission settings. Select one based on your business requirements:- All: Grants the API key permission to call any model or application.
-
Custom: Allows you to configure an IP address whitelist and an accessible model scope.
By default, all IPv4 (
0.0.0.0/0) traffic is allowed. Support for IPv6 is available only in the China (Beijing) region.You can add up to 20 IPv4 or IPv6 addresses or CIDR blocks to the IP address whitelist.
-
After the key is created, the complete API key and API Host (service endpoint address) are displayed in a dialog box. You must copy or download and save them immediately. Keep them confidential. Anyone with your API key can make service requests on your behalf, which may incur charges. After you close the dialog box, you cannot view or copy the plaintext API key again. If the key is lost, reset it or create a new one.
An Alibaba Cloud account can view the API keys in all workspaces. A RAM user can view only the API keys in the workspaces that they have joined.
API key management operations
API key management operations
- Edit: Modify the description and permission settings of the API key.
- Delete: Permanently delete the API key. This operation cannot be undone.
- Disable (not supported in the US (Virginia) region): Suspend the API key without deleting it. You can re-enable it at any time.
- Reset (not supported in the US (Virginia) region): Generate a new key value. The old key becomes invalid immediately.
When to use other owner accounts or workspaces
When to use other owner accounts or workspaces
- Workspace: A workspace is used to isolate resources and permissions for different projects or teams. To control which models a user group can call or to allocate costs for model calls, create or select a sub-workspace from the list.
Configure API key as an environment variable
We recommend setting your API key as an environment variable. This helps you avoid hard-coding the key in your source code, reducing the risk of accidental exposure.
- Linux
- macOS
- Windows
- Permanent
- Temporary
- Run the following command to append the environment variable setting to the
~/.bashrcfile.
~/.bashrc file.Manual modification
Manual modification
~/.bashrc file.- Run the following command to apply the changes.
- Open a new terminal window and run the following command to verify that the environment variable is set.
Use an API key
- Method 1: Call models fromthird-party tools Configuration guides for common tools: Chatbox, Cline, Claude Code, Dify, OpenClaw, Postman, and Qwen Code.
- Method 2: Call models by using code When you call the Qwen API for the first time by using code, we recommend that you configure the API key as an environment variable to avoid hard-coding it in your code, which reduces the risk of leaks.
base_url in your SDK or HTTP request). Model Studio provides both OpenAI-compatible and Anthropic-compatible protocol interfaces. The base_url differs between the two protocols and varies by region. Refer to the documentation for the protocol you use:- OpenAI-compatible protocol: OpenAI compatible - Chat
- Anthropic-compatible protocol: Anthropic-compatible Messages
API key security upgrade
Model Studio has upgraded the pay-as-you-go API key generation and storage mechanism for enhanced security (except for the US (Virginia) region). API keys created before the upgrade that start with sk- remain fully functional and are not affected. All API keys created after the upgrade start with sk-ws.
The following table describes the main differences between API keys created before and after the upgrade.
Comparison item | Pre-upgrade keys | Post-upgrade keys |
|---|---|---|
Key format | Starts with | Starts with |
Plaintext viewing | You can copy the complete plaintext key from the console at any time. | The plaintext key is displayed only once upon creation. It cannot be viewed again after the dialog box is closed. If lost, reset or create a new key. |
Calling capability | Can be used to call models normally; functionality is unaffected. | Can be used to call models normally; functionality is identical to pre-upgrade keys. |
Recommended action | We recommend that you create a new key to replace the old one for improved security. | Copy and save the key immediately after creation, and store it securely. |
Manage API keys through the API
In addition to console operations, Alibaba Cloud Model Studio provides OpenAPI operations that let you create, query, edit, delete, enable, disable, and reset API keys programmatically, so that you can integrate API key management into automated workflows.
Operation | Description |
|---|---|
Creates an API key. | |
Queries the information of a specified API key. | |
Queries the list of API keys. | |
Edits an API key, such as its description and permission configuration. | |
Deletes an API key. This operation cannot be undone. | |
Enables an API key (not supported in the US (Virginia) region). | |
Disables an API key. The key is retained and can be re-enabled at any time (not supported in the US (Virginia) region). | |
Resets an API key. A new key value is generated and the old key immediately becomes invalid (not supported in the US (Virginia) region). |
API key permissions
An API key's permissions are determined entirely by its workspace. All API keys within the same workspace have identical permissions. You do not need to create different API keys for different models, such as text-to-text, text-to-image, or speech synthesis models.
- API key in the default workspace: Can call all standard models and any application within the default workspace.
- API key in a sub-workspace: Can call standard models authorized for the sub-workspace and any application within that sub-workspace.
- IP address whitelist: Allows only IP addresses on the whitelist to use the API key to make calls (supports IPv4 addresses and CIDR blocks; IPv6 is supported only in the China (Beijing) region, and the US (Virginia) region supports IPv4 only).
- Access Scope: Select the specific models or applications that this API key can access. The key cannot call unselected resources.
API key validity
API keys do not expire. They remain valid until you manually delete them.
To grant temporary access to third-party applications or users, or to strictly control high-risk operations such as accessing or deleting sensitive data, you can generate a temporary API key (valid for 60 seconds). This avoids exposing a long-term API key and reduces the risk of leaks.
Error codes
If a model call fails and returns an error message, see Error codes for troubleshooting.
FAQ
Q: How many API keys can I create under a single Alibaba Cloud account?
A: For the Singapore, China (Beijing), China (Hong Kong), Japan (Tokyo), and Germany (Frankfurt) regions, each Alibaba Cloud account can create up to 50 API keys per region.
For the US (Virginia) region, each owner account, including the Alibaba Cloud account, can create up to 20 API keys.
Q: Are API keys created by a RAM user still valid after the user is deleted?
A: No. After you disable or delete a RAM user in the RAM console, all API keys created by that user become invalid and can no longer be used for model calls.
Q: I used theechocommand and confirmed the environment variable was set correctly. Why does my code still report that the API key cannot be found?
A: This can occur for the following reasons:
- Scenario 1: A temporary environment variable was set. A temporary variable is valid only within the current terminal session and does not affect running IDEs or other applications. Refer to the instructions in this topic to set a permanent environment variable.
-
Scenario 2: The IDE, command-line tool, or application was not restarted.
- You must restart your IDE (such as VS Code) or terminal to load the new environment variables.
- If you set the environment variable after deploying an application, you must restart the application service to reload the environment variables.
- Scenario 3: The variable is missing from a service configuration file. If your application is started by a service manager, such as systemd or supervisord, you may need to add the environment variable to the service manager's configuration file.
-
Scenario 4: Using the
sudocommand. If you usesudo python xx.pyto run the script, the environment variables of the current user may not be inherited. This is becausesudodoes not inherit all environment variables by default. You can use thesudo -E python xx.pycommand, where the-Eparameter ensures that the environment variables are passed. If you have permission to run the script, you can runpython xx.pydirectly.
icon next to an API key to copy the masked key.