Available in VPC
An API Key is an authentication method used when external programs or automation tasks that do not log in to the ML expert Platform console access ML expert Platform resources. Used for Model Registry CLI/SDK, Data Manager SDK, Pipelines SDK, and calls to private inference endpoints.
This guide describes the types and permission models of API Keys, methods for issuance, view, and deletion, and how to use them for each service.
API Key types
API Keys are divided into two types based on the issuance scope. Select the type based on where the resource you want to access belongs.
| Type | Issuance location | Access target | Token format |
|---|---|---|---|
| Project API Key | Project > Home > API Key tab | Models, inference endpoints, and Pipelines belonging to the Project | Starts with mlx-prj_ |
| Workspace API Key | Workspace > Dashboard > API Keys tab | Models and Data Manager datasets belonging to the Workspace | Starts with mlx-wrk_ |
- Datasets are Workspace-owned resources and can only be accessed with a Workspace API Key.
- Inference endpoints and Pipelines are Project-owned resources and can only be accessed with a Project API Key.
- Multiple permissions can be included in a single API Key. If you need to access resources from different Workspaces or Projects, issue an API Key for each.
Account-level API Keys (starting with mlx-) that were issued from the Workspace Dashboard in previous versions can no longer be newly issued. Existing keys can be used until their expiration time; replace them with a Project API Key or Workspace API Key from this guide before they expire.
Permission model
Permissions are specified for the API key as a combination of resource type (Type), scope (Scope), and target (Target). The API Key works only within the specified permission scope, and other requests are denied.
Permissions that can be specified for a Project API Key
| Resource type | Scope | Description | Target |
|---|---|---|---|
| Model | reader, writer | View model (reader), create/upload/delete model (writer) in Project Model Registry. | Model name |
| InferenceService | invoke | Call inference endpoint. | InferenceService name |
| LLMInferenceService | invoke | Call LLM inference endpoint. | LLMInferenceService name |
| KubeflowPipeline | writer | Call Pipelines APIs (including creating experiments and runs). | Cannot specify (Project-wide) |
Permissions for Workspace API Key
| Resource type | Scope | Description | Target |
|---|---|---|---|
| Model | reader, writer | View model (reader), create/upload/delete model (writer) in Workspace Model Registry. | Model name |
| Dataset | reader, writer, admin | Read dataset (reader), create/upload dataset, create Tag/Branch (writer), delete dataset (admin). | Dataset name |
A higher scope includes a lower scope (admin ⊇ writer ⊇ reader).
Rules for specifying target
- If a target is specified, permissions apply only to the resource with the matching name.
- If a target is not specified, permissions apply to all resources of the same type within the Project or Workspace.
- Targets are applied based on the resource name. If a name that does not exist at the time of issuance is specified, permissions will apply when a resource with the same name is created later.
- KubeflowPipeline does not support specifying a target and is always applied to the entire project.
The permissions, validity period, and type of an API key cannot be changed after issuance. To change permissions, delete the existing API key and issue a new one.
API Key management permissions
Only users with the Admin role for the relevant project or workspace can view API key lists, view tokens, and issue or delete keys. The API Key tab is not displayed for the Writer and Reader roles because the API key list contains original token text.
| Task | Project API Key | Workspace API Key |
|---|---|---|
| View list, view token, issue, delete. | Project Admin | Workspace Admin |
For how to assign roles, see Members and Member Settings.
Issue an API Key
To issue a Project API Key: Workspace API keys are issued in the same way on the Workspace > Dashboard > API Keys tab.
- Select a project in the ML expert Platform console and navigate to the Home > API Key tab.
- Click Add at the top of the list. If there are no issued keys, click the Add button in the center of the page.
- In the Issue API Key popup, enter the following information.
- API Key name: Enter up to 63 characters using lowercase letters (a–z), numbers (0–9), and hyphens (-). Must begin and end with a lowercase letter or number.
- Expiration period (days): Enter an integer between 1–365, or select one of 7d, 30d, 90d, or 365d to the right of the entry field. The default value is 30 days, and the scheduled expiration time is displayed below the entry field.
- Description (optional): Record the usage or recipient in up to 256 characters.
- Permissions: Select the resource type, permission level, and target. To add more permission rows, click the Add Permission button. You must add at least 1 permission, and the same (resource type, permission level) combination can only be added once.
- Click Issue.
- Immediately after creation, the status of the list may be displayed as Issuing. You can check the token by refreshing the list after a moment.
- The maximum value for the expiration period may vary depending on the platform operation settings. The default upper limit is 365 days.
- The expiration period is calculated from the time of issuance and cannot be extended. If you need to continue using it after expiration, issue a new API Key and replace the key in the usage location before it expires.
View API Key
The list in the Home > API Key tab (Dashboard > API Keys tab for Workspace) displays the API Key name, Permissions, Expiration At (expiration time), status, issuer, and description. To check the token value:
- Click View for the API Key row to check in the list.
- Check the name, issuer, description, expiration time, Permissions, and token in the View API Key window, and then click OK.
To copy only the token to the clipboard, click Copy in the row.
The statuses in the list are as follows:
| Status | Description |
|---|---|
| Issuing | The token is being created. Check again after a moment. |
| Expiring soon | The API Key is nearing its expiration time. Prepare for replacement. |
| Expired | The API Key has expired. It cannot be used for authentication and can be deleted. |
| Currently missing | This badge is displayed in the Permissions column. This means that the resource with the name specified as the target of the permission does not currently exist. Permissions will be applied once a resource with the same name is created. |
Treat tokens like passwords. Do not leave tokens in source code repositories, chats, or documentation. If a leak is suspected, delete it immediately and issue a new one.
Delete an API Key
If you delete an API Key, requests incoming with that token are immediately rejected.
- Home > API Key tab (in Workspace, Dashboard > API Keys tab).
- Select the checkbox for the API Key row to delete from the list. You can only select 1 at a time.
- Click Delete at the top of the list.
- Click Delete in the Delete API Key window.
Delete expired API Keys in the same way.
Using an API Key
API Keys are passed as Bearer tokens in the Authorization header of HTTP requests. The following describes how to use for each service:
Calling inference endpoints
To operate an inference endpoint privately, set the following annotations on InferenceService or LLMInferenceService: If an annotation is not set, the endpoint can be called without authentication.
metadata:
annotations:
mlx.navercorp.com/access-mode: restricted
Private endpoints can be called in the following two ways:
- Project API Key with
invokepermission for targetInferenceService(orLLMInferenceService) - Kubeconfig token of the corresponding Project member
Examples of calling with a Project API Key are as follows: Check the endpoint URL in the IngressRoute of the deployed service. For information on deploying inference services and setting IngressRoute, see Serving.
curl -H "Authorization: Bearer {API Key}" \
-H "Content-Type: application/json" \
https://{inference endpoint URL}/v1/models/{InferenceService name}:predict \
--data-binary @input.json
invoke permissions on InferenceService apply to the entire predictor, transformer, and explainer components. If you delete the annotation from restricted or change it to public, you can call it without authentication again.
Pipelines SDK
To run a pipeline with the Pipelines SDK outside the ML expert Platform (local PC, CI server, etc.), a Project API Key with writer permissions for KubeflowPipeline is required.
import kfp
client = kfp.Client(
host="https://{ML expert Platform domain}/pipeline",
existing_token="{API Key}",
namespace="p-{Project name}",
)
- If you call with an API Key that does not have
KubeflowPipelinepermissions, a403 APIKey does not grant KubeflowPipeline accesserror occurs. Permissions cannot be added after issuance, so issue a new API Key. - Workspace API Keys cannot be used for the Pipelines API.
- A
403 project serviceaccount not provisionederror may occur immediately after creating a Project. Try again after a moment.
For information on how to write a pipeline, see Pipelines.
Model Registry CLI/SDK
The Model Registry CLI/SDK sets an API Key with the MLX_APIKEY environment variable or mlx configure command.
export MLX_ENDPOINT_URL="https://{ML expert Platform domain}"
export MLX_APIKEY="{API Key}"
- A Project API Key with
Modelpermission is used for Project models, and a Workspace API Key withModelpermission is used for Workspace models. readerpermission is required for viewing and downloading models, andwriterpermission is required for creating models/versions and uploading/deleting files.- Insert an API Key with
Modelreaderpermissions into thestorage-configSecret used when the inference service downloads a model from the Model Registry.
For details, see Model Registry.
Data Manager SDK
Data Manager SDK logs in with an authorized Workspace API Key Dataset.
from mlx.sdk.data import login
login("{API Key}", "{ML expert Platform domain}")
| Task | Required Permission Level |
|---|---|
| View dataset list and details, download. | reader |
| Create and upload datasets, create tags and branches. | writer |
| Deleting a dataset. | admin |
To allow only specific datasets, specify the dataset name as the target of the permission. For details, see the Data Manager documentation.
Compare API Key and kubeconfig
ML expert Platform also provides project units in addition to API keys kubeconfig. Select according to your purpose.
| Item | API Key | kubeconfig |
|---|---|---|
| Purpose | External programs and automation tasks access Model Registry, Data Manager, Pipelines, and inference endpoints | User creates and views workloads in Project Namespace through kubectl. |
| Permission criteria | Resource type, permission level, and target specified during issuance | User's Project member role (Admin/Writer/Reader). |
| Issuing entity | Project or Workspace Admin | Project member themselves. |
| Expiration period | 1–365 days (default: 30 days) | 1 day-operational configuration upper limit (default: 90 days). |
| Revocation before expiration | Invalid immediately upon deletion | Not possible (only permissions are revoked if excluded from members). |
For instructions on how to issue kubeconfig, see Overview.
Troubleshooting
| Symptom | Cause | Solution |
|---|---|---|
| API Key tab not visible on the console | Not in Admin role. | Request issuance to Project or Workspace Admin. |
| 401 error | Token typo, expired API Key, or deleted API Key. | Check status on the console and issue a new one if necessary. |
| 403 error | The API Key lacks permissions or a target for the requested resource, or a different type of API Key was used (e.g., calling Pipelines with a Workspace API Key). | Issue a new API Key of the correct type containing the necessary permissions and targets. |
| Dataset deletion is denied with a 403 error | Dataset Privilege level is not admin. |
Issue a Workspace API Key with Dataset admin permissions. |
| Token not visible immediately after issuance | Creating token. | Refresh the list after a moment. |