Why it matters
luv13 is prepaid. Anyone holding your key can make requests that draw down your balance at $0.33 per 1M tokens, on any of the seven models.
Do
- Store it in the environment.
export LUV13_API_KEY=sk-luv13-...in your shell, or your host's secret settings in production. See Environment Variables. - Keep
.envfiles out of git. Add.envto.gitignorebefore the first commit. - Call luv13 from your server. If a browser app needs model output, have your backend make the request. See Browser Requests.
- Watch your usage in the dashboard. A jump you don't recognize can mean a leaked key.
Don't
- Paste the key into chats, tickets, screenshots or public repos.
- Log full request headers. Mask the key if you log requests at all.
- Put the key in a URL. URLs end up in logs and browser history. Send it in the
Authorization: Bearerheader, the way luv13.ai/docs shows.
If a key leaks
- Create a new key in the dashboard and switch your apps to it.
- Check recent usage in the dashboard for requests you didn't make.
- Email [email protected] about the leaked key.
Quick test
curl -s -o /dev/null -w "%{http_code}\n" https://api.luv13.ai/v1/chat/completions \
-H "Authorization: Bearer $LUV13_API_KEY" \
-H "Content-Type: application/json" \
-d '{"model": "luv13/glm-5.3-flash", "messages": [{"role": "user", "content": "ping"}]}'401 means the key is missing, wrong or not being sent. When the key works, this request is billed like any other.
