Customer API keys
A customer API key is a Gateway key bound to one customer, so its requests need no customer field. Give one to each tenant so a leaked key exposes only that tenant.
Mint a key
POST /v1/customers/{customer_id}/api-keys with your organization-level key. The raw key comes back once, in key.
A customer can hold 5 keys; a sixth returns 409 customer_api_key_limit_reached, and minting for an inactive customer returns 400 customer_inactive. GET on the same path lists keys without secrets. The customer then calls Gateway as usual:
A customer value that contradicts the key returns 400 customer_mismatch.
Rotate or revoke a key
To rotate without downtime, mint a new key, move the customer onto it, then revoke the old one with DELETE /v1/customers/{customer_id}/api-keys/{key_id}. Deleting a customer revokes its keys; deactivating it makes them return 403 until reactivated.
What a customer key can reach
Other customers’ paths return 404, so tenants can’t discover each other, and organization-level routes return 403 customer_scoped_key_forbidden.
Its usage shows only customer_byok_spend and request_count, and its key list only the customer’s own vendor keys, hiding what you pay and which keys you hold.