Skip to main content
Every partner API call needs an API key, sent as a bearer token:
The API has no session cookie and no CORS. A key is the only way in.

Creating a key

In the dashboard, go to Settings → API keys (/app/settings/api-keys) and select + New key. Give it a name, pick one or more scopes, then create it.
The key is shown once, immediately after creation. Copy it before you close the dialog. GPU Outlet stores only its hash, so a lost key cannot be recovered. Revoke it and create a new one.
You can hold up to 10 active keys per user. A revoked key does not count toward the 10 active keys. Its name stays taken. Never truncate a key when you log or display it.

GET /me

The cheapest way to confirm a key works and see what it can do. No scope is required.
Response
rate_limit_per_min is null unless your key has a custom limit. Otherwise the default limit applies.

Company context

A key belongs to a person, not to a company. A call acts with that person’s company and role, exactly as in the dashboard. Nothing in a request body can name a company.
  • If the key’s owner is not a member of any company, every company-scoped call fails with company_required.
  • If the owner’s role does not allow the action, the call fails with forbidden_role. A viewer can read. Stating demand, declining an opportunity or confirming readiness needs a trader, an authorized signatory or an owner.

Scopes

A key keeps the scopes it was created with. To add a scope, create a new key. A call without the required scope fails with insufficient_scope, and required_scope names the scope. A new key starts with radar:read ticked and everything else unticked. GET /me needs no scope.

Revoking a key

Revoke a key on the same Settings → API keys page. From then on, the key answers every call with api_key_revoked. A revoked key is not deleted: it stays in the list and its name stays taken.

API quickstart

Use a key end to end: state demand, read it back.

Rate limits

Per-key, per-day and per-IP limits, and the headers that report them.

Errors

Every error code this API returns, including company_required and forbidden_role.

Idempotency

Which writes need an Idempotency-Key.