API Key management

Prev Next

Available in VPC

An API Key is an authentication method used when external programs or automation tasks that do not log in to the ML expert Platform console access ML expert Platform resources. Used for Model Registry CLI/SDK, Data Manager SDK, Pipelines SDK, and calls to private inference endpoints.

This guide describes the types and permission models of API Keys, methods for issuance, view, and deletion, and how to use them for each service.

API Key types

API Keys are divided into two types based on the issuance scope. Select the type based on where the resource you want to access belongs.

Type Issuance location Access target Token format
Project API Key Project > Home > API Key tab Models, inference endpoints, and Pipelines belonging to the Project Starts with mlx-prj_
Workspace API Key Workspace > Dashboard > API Keys tab Models and Data Manager datasets belonging to the Workspace Starts with mlx-wrk_
  • Datasets are Workspace-owned resources and can only be accessed with a Workspace API Key.
  • Inference endpoints and Pipelines are Project-owned resources and can only be accessed with a Project API Key.
  • Multiple permissions can be included in a single API Key. If you need to access resources from different Workspaces or Projects, issue an API Key for each.
Note

Account-level API Keys (starting with mlx-) that were issued from the Workspace Dashboard in previous versions can no longer be newly issued. Existing keys can be used until their expiration time; replace them with a Project API Key or Workspace API Key from this guide before they expire.

Permission model

Permissions are specified for the API key as a combination of resource type (Type), scope (Scope), and target (Target). The API Key works only within the specified permission scope, and other requests are denied.

Permissions that can be specified for a Project API Key

Resource type Scope Description Target
Model reader, writer View model (reader), create/upload/delete model (writer) in Project Model Registry. Model name
InferenceService invoke Call inference endpoint. InferenceService name
LLMInferenceService invoke Call LLM inference endpoint. LLMInferenceService name
KubeflowPipeline writer Call Pipelines APIs (including creating experiments and runs). Cannot specify (Project-wide)

Permissions for Workspace API Key

Resource type Scope Description Target
Model reader, writer View model (reader), create/upload/delete model (writer) in Workspace Model Registry. Model name
Dataset reader, writer, admin Read dataset (reader), create/upload dataset, create Tag/Branch (writer), delete dataset (admin). Dataset name

A higher scope includes a lower scope (admin ⊇ writer ⊇ reader).

Rules for specifying target

  • If a target is specified, permissions apply only to the resource with the matching name.
  • If a target is not specified, permissions apply to all resources of the same type within the Project or Workspace.
  • Targets are applied based on the resource name. If a name that does not exist at the time of issuance is specified, permissions will apply when a resource with the same name is created later.
  • KubeflowPipeline does not support specifying a target and is always applied to the entire project.
Caution

The permissions, validity period, and type of an API key cannot be changed after issuance. To change permissions, delete the existing API key and issue a new one.

API Key management permissions

Only users with the Admin role for the relevant project or workspace can view API key lists, view tokens, and issue or delete keys. The API Key tab is not displayed for the Writer and Reader roles because the API key list contains original token text.

Task Project API Key Workspace API Key
View list, view token, issue, delete. Project Admin Workspace Admin

For how to assign roles, see Members and Member Settings.

Issue an API Key

To issue a Project API Key: Workspace API keys are issued in the same way on the Workspace > Dashboard > API Keys tab.

  1. Select a project in the ML expert Platform console and navigate to the Home > API Key tab.
  2. Click Add at the top of the list. If there are no issued keys, click the Add button in the center of the page.
  3. In the Issue API Key popup, enter the following information.
    • API Key name: Enter up to 63 characters using lowercase letters (a–z), numbers (0–9), and hyphens (-). Must begin and end with a lowercase letter or number.
    • Expiration period (days): Enter an integer between 1–365, or select one of 7d, 30d, 90d, or 365d to the right of the entry field. The default value is 30 days, and the scheduled expiration time is displayed below the entry field.
    • Description (optional): Record the usage or recipient in up to 256 characters.
    • Permissions: Select the resource type, permission level, and target. To add more permission rows, click the Add Permission button. You must add at least 1 permission, and the same (resource type, permission level) combination can only be added once.
  4. Click Issue.
    • Immediately after creation, the status of the list may be displayed as Issuing. You can check the token by refreshing the list after a moment.
Note
  • The maximum value for the expiration period may vary depending on the platform operation settings. The default upper limit is 365 days.
  • The expiration period is calculated from the time of issuance and cannot be extended. If you need to continue using it after expiration, issue a new API Key and replace the key in the usage location before it expires.

View API Key

The list in the Home > API Key tab (Dashboard > API Keys tab for Workspace) displays the API Key name, Permissions, Expiration At (expiration time), status, issuer, and description. To check the token value:

  1. Click View for the API Key row to check in the list.
  2. Check the name, issuer, description, expiration time, Permissions, and token in the View API Key window, and then click OK.

To copy only the token to the clipboard, click Copy in the row.

The statuses in the list are as follows:

Status Description
Issuing The token is being created. Check again after a moment.
Expiring soon The API Key is nearing its expiration time. Prepare for replacement.
Expired The API Key has expired. It cannot be used for authentication and can be deleted.
Currently missing This badge is displayed in the Permissions column. This means that the resource with the name specified as the target of the permission does not currently exist. Permissions will be applied once a resource with the same name is created.
Caution

Treat tokens like passwords. Do not leave tokens in source code repositories, chats, or documentation. If a leak is suspected, delete it immediately and issue a new one.

Delete an API Key

If you delete an API Key, requests incoming with that token are immediately rejected.

  1. Home > API Key tab (in Workspace, Dashboard > API Keys tab).
  2. Select the checkbox for the API Key row to delete from the list. You can only select 1 at a time.
  3. Click Delete at the top of the list.
  4. Click Delete in the Delete API Key window.

Delete expired API Keys in the same way.

Using an API Key

API Keys are passed as Bearer tokens in the Authorization header of HTTP requests. The following describes how to use for each service:

Calling inference endpoints

To operate an inference endpoint privately, set the following annotations on InferenceService or LLMInferenceService: If an annotation is not set, the endpoint can be called without authentication.

metadata:
  annotations:
    mlx.navercorp.com/access-mode: restricted

Private endpoints can be called in the following two ways:

  • Project API Key with invoke permission for target InferenceService (or LLMInferenceService)
  • Kubeconfig token of the corresponding Project member

Examples of calling with a Project API Key are as follows: Check the endpoint URL in the IngressRoute of the deployed service. For information on deploying inference services and setting IngressRoute, see Serving.

curl -H "Authorization: Bearer {API Key}" \
  -H "Content-Type: application/json" \
  https://{inference endpoint URL}/v1/models/{InferenceService name}:predict \
  --data-binary @input.json
Note

invoke permissions on InferenceService apply to the entire predictor, transformer, and explainer components. If you delete the annotation from restricted or change it to public, you can call it without authentication again.

Pipelines SDK

To run a pipeline with the Pipelines SDK outside the ML expert Platform (local PC, CI server, etc.), a Project API Key with writer permissions for KubeflowPipeline is required.

import kfp

client = kfp.Client(
    host="https://{ML expert Platform domain}/pipeline",
    existing_token="{API Key}",
    namespace="p-{Project name}",
)
  • If you call with an API Key that does not have KubeflowPipeline permissions, a 403 APIKey does not grant KubeflowPipeline access error occurs. Permissions cannot be added after issuance, so issue a new API Key.
  • Workspace API Keys cannot be used for the Pipelines API.
  • A 403 project serviceaccount not provisioned error may occur immediately after creating a Project. Try again after a moment.

For information on how to write a pipeline, see Pipelines.

Model Registry CLI/SDK

The Model Registry CLI/SDK sets an API Key with the MLX_APIKEY environment variable or mlx configure command.

export MLX_ENDPOINT_URL="https://{ML expert Platform domain}"
export MLX_APIKEY="{API Key}"
  • A Project API Key with Model permission is used for Project models, and a Workspace API Key with Model permission is used for Workspace models.
  • reader permission is required for viewing and downloading models, and writer permission is required for creating models/versions and uploading/deleting files.
  • Insert an API Key with Model reader permissions into the storage-config Secret used when the inference service downloads a model from the Model Registry.

For details, see Model Registry.

Data Manager SDK

Data Manager SDK logs in with an authorized Workspace API Key Dataset.

from mlx.sdk.data import login

login("{API Key}", "{ML expert Platform domain}")
Task Required Permission Level
View dataset list and details, download. reader
Create and upload datasets, create tags and branches. writer
Deleting a dataset. admin

To allow only specific datasets, specify the dataset name as the target of the permission. For details, see the Data Manager documentation.

Compare API Key and kubeconfig

ML expert Platform also provides project units in addition to API keys kubeconfig. Select according to your purpose.

Item API Key kubeconfig
Purpose External programs and automation tasks access Model Registry, Data Manager, Pipelines, and inference endpoints User creates and views workloads in Project Namespace through kubectl.
Permission criteria Resource type, permission level, and target specified during issuance User's Project member role (Admin/Writer/Reader).
Issuing entity Project or Workspace Admin Project member themselves.
Expiration period 1–365 days (default: 30 days) 1 day-operational configuration upper limit (default: 90 days).
Revocation before expiration Invalid immediately upon deletion Not possible (only permissions are revoked if excluded from members).

For instructions on how to issue kubeconfig, see Overview.

Troubleshooting

Symptom Cause Solution
API Key tab not visible on the console Not in Admin role. Request issuance to Project or Workspace Admin.
401 error Token typo, expired API Key, or deleted API Key. Check status on the console and issue a new one if necessary.
403 error The API Key lacks permissions or a target for the requested resource, or a different type of API Key was used (e.g., calling Pipelines with a Workspace API Key). Issue a new API Key of the correct type containing the necessary permissions and targets.
Dataset deletion is denied with a 403 error Dataset Privilege level is not admin. Issue a Workspace API Key with Dataset admin permissions.
Token not visible immediately after issuance Creating token. Refresh the list after a moment.