API keys: what they are and how to keep them safe
An API key is a secret string that identifies your account to an API and authorizes requests, so anyone holding it can use and spend your account.
What an API key is
An API key works like a password that programs send with each request. The server uses it to know who is calling, which limits apply, and which balance to charge. Wild West API keys start with sk-ww-. Anyone who has your key can make requests on your account until you revoke it, so treat it like a password.
How it is sent
OpenAI-compatible APIs expect the key in the Authorization header as a bearer token:
curl https://wildwestapi.com/v1/chat/completions \
-H "Authorization: Bearer sk-ww-..." \
-H "Content-Type: application/json" \
-d '{"model": "glm-5.3-outlaw", "messages": [{"role": "user", "content": "Hi"}]}'Anthropic-style clients usually send the key in an x-api-key header when calling /v1/messages. Check the docs for which headers each endpoint accepts. In SillyTavern you paste the key into the API key field of the connection panel, and SillyTavern's server stores it in its secrets file and sends it for you.
Keeping it safe
- Never put a key in client-side JavaScript, a public repo, a screenshot, or a shared SillyTavern settings export.
- Store it in an environment variable or a secrets file outside version control.
- Use a separate key per app or device, so you can revoke one without breaking the others and see which one is used.
- If you expose SillyTavern over a network, turn on its login or whitelist; otherwise anyone who reaches it can use your key.
- Be careful with shared computers and pasted logs. Debug output that prints request headers will include the key.
If a key leaks
Revoke it in your dashboard immediately and create a new one, then update your apps. Check recent usage for requests you did not make. Deleting the key from a git commit is not enough; it stays in history and automated scanners find leaked keys within minutes.
Common mistakes
- Extra spaces or a missing character when pasting. A
401error usually means the key is wrong, revoked, or sent in the wrong header. - Typing "Bearer" into a field that already adds it, producing "Bearer Bearer sk-ww-...".
- Using a key in a browser-only frontend. Wild West API does not answer CORS today, so direct browser calls fail anyway; route requests through a backend such as SillyTavern's server.
FAQ
Where do I put my API key in SillyTavern?
In the API Connections panel, under Chat Completion with the Custom (OpenAI-compatible) source, in the API key field next to the custom endpoint URL.
What does a 401 error mean?
The API did not accept your key. It may be mistyped, revoked, or sent in the wrong header.