Authentication
Every proxy call needs Authorization: Bearer fz_…. The token is a Fuse key for one project. Fuse stores only its SHA-256. The full value is shown once, when you create it.
curl https://fuse.ospalabs.com/v1/chat/completions \
-H "Authorization: Bearer fz_..." \
-H "Content-Type: application/json" \
-d '{"model":"gpt-4.1-mini","messages":[{"role":"user","content":"hi"}]}'A missing, malformed, unknown, or revoked key is 401 invalid_fuse_key. The provider is not called.
The header has to be exactly Bearer, one space, then the key. fz_ is required. Extra spaces, a provider key, or a key from another project all fail the same way.
Failed checks are counted. After too many from the same client, Fuse answers 429 rate_limited for about a minute and does not look the key up again. A valid key that is merely over its own per-minute limit is a different 429: the message says the Fuse key is over its request limit.
Revoke a leaked key in the dashboard. The proxy drops it from its cache within about 15 seconds. Create a new key for the app. The old value cannot be shown again.