API tokens are the primary authentication mechanism for the Infere platform. Each token is a secret key that carries its own configuration - model routing, a spending budget, rate limits, an IP allowlist, optional LLM security scanning, and an optionally deployed prompt.

Token Types

  • Personal token - owned by you in your personal workspace.
  • Organization token - owned by an organization and assignable to a specific member.
  • Workspace default token - marked as the default for its workspace, used by the Playground and in-app tools.

Token Features

  • Model routing - routing mode (balanced, cost-optimized, speed-optimized, quality-first, throughput-optimized), optional Auto-Routing, preferred/excluded/fallback models, and provider order.
  • Token budgets - spending caps with daily, weekly, or monthly periods, a warning threshold (50–95%), and optional hard limits that block requests.
  • Rate limits - requests per minute/hour/day, tokens per minute, and max concurrent requests.
  • IP allowlisting - restrict a token to specific IPs or CIDR ranges.
  • LLM security scanning - optional prompt-injection / unsafe-content scanning with a threat threshold and block-or-monitor mode.
  • PII & compliance - redact or block PII, restrict routing to GDPR/HIPAA-compliant providers, and enforce data residency.
  • Prompt deployment - deploy one prompt per token; its messages are prepended to every chat request automatically.
  • Configurable expiration and instant revocation (revoke is reversible; delete is permanent).

Budget Configuration

{

  "name": "production-api",

  "budget": {

    "enabled": true,

    "limit": 250,           // $250 spending cap

    "period": "monthly",

    "warningThreshold": 80,   // flag at 80%

    "hardLimit": true      // block requests once reached

  },

  "rateLimits": {

    "requestsPerMinute": 600,

    "maxConcurrent": 50

  }

}

Create tokens with the Quick Dev Token one-click path or the five-step Advanced Wizard (template → configure → routing → security → review). The token secret is shown only once at creation - store it securely.