Authentication

Every proxy call needs Authorization: Bearer fz_…. The token is a Fuse key for one project. Fuse stores only its SHA-256. The full value is shown once, when you create it.

curl https://fuse.ospalabs.com/v1/chat/completions \
  -H "Authorization: Bearer fz_..." \
  -H "Content-Type: application/json" \
  -d '{"model":"gpt-4.1-mini","messages":[{"role":"user","content":"hi"}]}'

A missing, malformed, unknown, or revoked key is 401 invalid_fuse_key. The provider is not called.

The header has to be exactly Bearer, one space, then the key. fz_ is required. Extra spaces, a provider key, or a key from another project all fail the same way.

Failed checks are counted. After too many from the same client, Fuse answers 429 rate_limited for about a minute and does not look the key up again. A valid key that is merely over its own per-minute limit is a different 429: the message says the Fuse key is over its request limit.

Revoke a leaked key in the dashboard. The proxy drops it from its cache within about 15 seconds. Create a new key for the app. The old value cannot be shown again.