Get started
Authentication
API keys, key purposes, device login, and how each surface authenticates.
Every request to Faelith is authenticated with a bearer API key. Keys are created in Dashboard → API Keys and are shown once at creation; store them in a secret manager.
Authorization: Bearer sk-fae_...Key purposes#
Each key has one purpose. The purpose decides which meter the request debits and which surfaces accept it.
| Purpose | Accepted by | Debits |
|---|---|---|
code | CLI, desktop Code | Code 5-hour / weekly meters |
chat | Desktop Chat, web Chat | Chat 5-hour / weekly meters |
api | /v1/* from your own software | Prepaid wallet at list price |
A key never crosses purposes: a chat key cannot drive Code, and an api key is the only kind that reaches your wallet.
Data handling#
Every key uses the same ZDR inference path. Faelith separately retains complete encrypted model I/O and the complete chat transcript in its own S3 for 90 days. See Data handling.
Device login#
The CLI and desktop app can sign in without copying a key:
- The client calls
POST /api/cli/deviceand receives adevice_codeplus a shortuser_code. - You open
https://faelithindustries.com/cli/loginwhile signed in, type the code and approve. - The client polls
POST /api/cli/device/polluntil it receives acode-purpose key.
Codes are short-lived. Approving a code you did not request is the only way to leak a key, so the page asks you to type the code and shows the IP, client and time of the request; approving also asks you to confirm it is you and emails you. See Account security.
Sign out#
/logout in the CLI or Log out in the app deletes the stored keys locally and returns to the sign-in screen. Revoke the key itself under API Keys if the machine is lost.
Found a mistake or a gap? Tell us and we will fix the page.