Authentication & Security
All API requests to ModelMart must be authenticated using an API Key passed in the HTTP Authorization header:
Authorization: Bearer mm_live_xxxxxxxxxxxxxxxxxxxxxxxx
1. Security Best Practices
- Never expose keys in client-side code: Do not use API keys directly in web frontend frameworks (React, Vue, browser apps) or mobile applications.
- Use Environment Variables: Always store keys in
.envfiles (excluded via.gitignore) or secret management systems (AWS Secrets Manager, Cloudflare Secrets, Vercel Env). - Revoke Compromised Keys Immediately: If a key is leaked or exposed publicly, revoke it immediately via the Dashboard and generate a new one.
# .env file MODELMART_API_KEY="mm_live_xxxxxxxxxxxxxxxxxxxx" MODELMART_BASE_URL="https://api.modelmart.io.vn/v1"
2. Spend Limits & Key Scoping
From the ModelMart Dashboard, you can configure granular controls on each API key:
- Monthly Budget Limits: Set a maximum spending ceiling per key. Requests are blocked with
402 balance_too_lowonce reached to prevent unexpected charges. - Model Whitelists: Restrict a key to specific models only (e.g., allow only
gemini-3.6-flashfor staging). - IP Whitelisting: Restrict API access to specific backend server IPs.
3. Zero Data Retention (ZDR) Policy
- No Prompt/Response Storage: ModelMart operates as a zero-retention routing gateway. We do not store or inspect the contents of your prompts or model responses.
- Metadata Only: We only log technical metadata required for billing and rate-limiting (Request ID, Timestamp, Model ID, Token counts, Latency, HTTP status).
- End-to-End Encryption: All traffic is encrypted using TLS 1.3.