โ ๏ธ Pending Update ยท 2026-08-29 Verification ยท Content may be outdated, please refer to official docs Updated: 2026-08-29 ยท Status: Pending Verification
Background
When applications talk directly to model providers, keys are scattered across config files, CI variables, and container envs. A single leak means a full rotation plus rolling restart, and different team members holding their own keys makes auditing painful. Funneling every key into the gateway changes the picture: clients see only one APISHARE_TOKEN, and rotation, revocation, and quota slicing all happen inside the gateway.
Core Design
- Two-layer tokens: the outer layer is the
APISHARE_TOKENissued to clients (long-lived, revocable); the inner layer is the upstream provider key (short-lived, rotatable). The two are decoupled, so rotating the inner layer never disturbs clients. - Key pool and rotation: each provider maintains a pool of keys bucketed by hash. Rotation shifts 10% of traffic to the new key first, watches 5xx/429 ratios, then decides on full cutover.
- Least privilege: each upstream key carries a
scope(read-models / invoke / billing-query); the client token also carries a scope, and the gateway enforces both layers. - Audit log: every key fetch is logged with timestamp, client ID, provider, and a key hash (never plaintext).
- Vault backend: keys are KMS-encrypted at rest, decrypted into memory on demand; plaintext never touches disk.
Code Example
import hashlib, time
class KeyVault:
def __init__(self, kms):
self.kms = kms
# provider -> list of encrypted key blobs
self.pool = {"groq": [...], "deepseek": [...]}
# rolling index for round-robin
self.idx = 0
def get(self, provider: str, client_id: str) -> str:
keys = self.pool[provider]
chosen = keys[self.idx % len(keys)]
self.idx += 1
plaintext = self.kms.decrypt(chosen)
self._audit(client_id, provider, plaintext)
return plaintext
def _audit(self, client_id, provider, key):
h = hashlib.sha256(key.encode()).hexdigest()[:12]
print(f"[audit] {time.time()} client={client_id} "
f"provider={provider} key={h}")
Rotation Safety Boundary
The biggest risk in key rotation is "rotating the wrong one" โ revoking a healthy key while leaving a bad one, or pushing a new key live before it activates, dropping traffic to zero. Safe boundary practice: rotate one key at a time, ramp traffic in four stages โ 1%, 10%, 50%, 100% โ each lasting an hour, watching the 401 ratio; rollback on anomaly. Maintain a "primary + standby" pool: a new key validates in the standby pool for 24 hours before being promoted to primary, eliminating "new key is bad key" scenarios.
Best Practices
- Rotation cadence: rotate free keys every 30 days and paid keys every 90 days; trigger an early rotation if anomalous 401 ratios cross threshold.
- Zero trust: even internal team members get only the client token โ they never see upstream key plaintext.
- Degradation plan: if KMS fails, keys already loaded in memory remain usable, but new keys must be blocked from the pool to prevent mis-rotation.
- Leak response: on detecting a leak, complete revocation and new-key activation within 5 minutes using a pre-written automation script.
Centralizing keys is not "putting all eggs in one basket" โ it is "replacing the basket with a vaulted room."
๐ Get Started: One-Click Free API Access
Want to call all the free models above with a single API key, no need to sign up for each provider? Apishare.cc provides a unified API Key โ one key, 100+ models, free models at zero cost.
๐ Register on Apishare.cc โ Get your unified API Key
๐ Want to see more free model rankings? Check out the Sep 2026 Free LLM API Rankings โ
Get Started: APIShare Free API Directory
- ๐ Claim your free credits: Register on APIShare ยท Sign in to console
- ๐ Browse every free API and live ranking: APIShare Free API Directory
- ๐ See the leaderboard: Free LLM API Rankings
About the Free API Aggregator
The models covered in this guide are all served through the APIShare free API aggregator, which gives you one key for the whole catalog.
- Full model catalog: APIShare free API directory
- Sign up for a free trial key: Register and claim your API key