Credentials
The header each platform expects, and how the safe-key is stored.
Every platform keeps its native auth scheme, so no client auth code has to change. The gateway accepts the platform's own header and looks the safe-key up by hash.
Auth scheme per platform
| Platform | Header | Value |
|---|---|---|
| OpenAI | Authorization | Bearer sk-safe-… |
| DeepSeek | Authorization | Bearer sk-safe-… |
| Claude | x-api-key | sk-safe-… |
| Claude | anthropic-version | Passed through; set to 2023-06-01 by the gateway when the client omits it |
| fal.ai | Authorization | Key sk-safe-… |
| ByteDance Seedance | Authorization | Bearer sk-safe-… |
Examples
Each example uses its platform's prefix, so the base URL is the only thing a client replaces.
curl https://sluiceline.com/anthropic/v1/messages \
-H "x-api-key: $SLUICELINE_SAFE_KEY" \
-H "anthropic-version: 2023-06-01" \
-H "Content-Type: application/json" \
-d '{"model":"claude-fable-5-1","max_tokens":256,"messages":[{"role":"user","content":"hi"}]}'Ark model IDs are date-stamped (dreamina-seedance-2-5-260628) and a new version
ships under a new ID rather than updating the old one, so check BytePlus's Model
list for the current ID instead of pinning one permanently.
How the safe-key is stored
| Property | Value |
|---|---|
| Lookup | By sha256(safe-key); the plaintext is never a stored identifier |
| At rest | Encrypted, so the dashboard can show it again after creation |
| Metadata | None: no user, platform or mode is encoded into the key |
| Rotation | Revoke it in the dashboard; the next request is rejected. Nothing has to expire |