Authentication & Security

All API requests to ModelMart must be authenticated using an API Key passed in the HTTP Authorization header:

Authorization: Bearer mm_live_xxxxxxxxxxxxxxxxxxxxxxxx

1. Security Best Practices

  • Never expose keys in client-side code: Do not use API keys directly in web frontend frameworks (React, Vue, browser apps) or mobile applications.
  • Use Environment Variables: Always store keys in .env files (excluded via .gitignore) or secret management systems (AWS Secrets Manager, Cloudflare Secrets, Vercel Env).
  • Revoke Compromised Keys Immediately: If a key is leaked or exposed publicly, revoke it immediately via the Dashboard and generate a new one.
# .env file
MODELMART_API_KEY="mm_live_xxxxxxxxxxxxxxxxxxxx"
MODELMART_BASE_URL="https://api.modelmart.io.vn/v1"

2. Spend Limits & Key Scoping

From the ModelMart Dashboard, you can configure granular controls on each API key:

  • Monthly Budget Limits: Set a maximum spending ceiling per key. Requests are blocked with 402 balance_too_low once reached to prevent unexpected charges.
  • Model Whitelists: Restrict a key to specific models only (e.g., allow only gemini-3.6-flash for staging).
  • IP Whitelisting: Restrict API access to specific backend server IPs.

3. Zero Data Retention (ZDR) Policy

  • No Prompt/Response Storage: ModelMart operates as a zero-retention routing gateway. We do not store or inspect the contents of your prompts or model responses.
  • Metadata Only: We only log technical metadata required for billing and rate-limiting (Request ID, Timestamp, Model ID, Token counts, Latency, HTTP status).
  • End-to-End Encryption: All traffic is encrypted using TLS 1.3.