> ## Documentation Index
> Fetch the complete documentation index at: https://www.tryleap.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Leap's API is at https://api.tryleap.ai. Send the key in the x-api-key header or as Authorization: Bearer; keys start with leap_.
> Take model IDs and input schemas from GET /v1/models/{creator}/{name}, or from https://api.tryleap.ai/v1/public/models without a key. Never guess an input field: unknown fields are a 400.
> Model inputs take uploaded file IDs (file_...), never URLs.
> To give a coding agent the whole API, install the Leap skill: curl -fsSL https://www.tryleap.ai/install.sh | sh
> The full OpenAPI 3.1 spec is at https://www.tryleap.ai/docs/openapi.json.

# Authentication

> Create an API key, send it in the x-api-key header or as a Bearer token, and know what it can do and when it expires.

Every request to `https://api.tryleap.ai/v1` needs an API key, except the [public catalog](#browse-without-a-key). Create one at [app.tryleap.ai/go/api](https://app.tryleap.ai/go/api).

Send the key in the `x-api-key` header, or as a Bearer token, the way most HTTP clients and SDKs send one:

<CodeGroup>
  ```bash x-api-key theme={"theme":"css-variables"}
  curl https://api.tryleap.ai/v1/credits -H "x-api-key: $LEAP_API_KEY"
  ```

  ```bash Bearer theme={"theme":"css-variables"}
  curl https://api.tryleap.ai/v1/credits -H "Authorization: Bearer $LEAP_API_KEY"
  ```
</CodeGroup>

Both work the same way, with the same scopes and rate limit. Send one or the other: two different keys in the two headers get a `400` with the code `conflicting_credentials`.

```json theme={"theme":"css-variables"}
{ "object": "credits", "available_usd": "4.67", "held_usd": "0.66" }
```

A key starts with `leap_`. It belongs to one workspace and spends that workspace's balance, so keep it on your server: read it from an environment variable, and never ship it in a browser, a mobile app or a repository.

## What a key can do

Every key gets the same scopes:

| Scope | Lets the key |
| - | - |
| `generations:read` | List models, get quotes, read generations, files and the balance |
| `generations:write` | Start, batch and cancel generations, upload files, and keep outputs as files |
| `workspace:read` | Read the workspace the key belongs to |

Each endpoint in the [API reference](/docs/api-reference/introduction) names the scope it needs. A key without it gets a `403` with the code `permission_denied`.

## Expiry and revoking

A new key lasts 365 days unless you choose 30 days, 90 days or never when you create it. You can revoke a key at any time from the same page. A request without a key gets a `401` with the code [`missing_api_key`](/docs/errors#missing_api_key), and an unknown, expired or revoked key gets [`invalid_api_key`](/docs/errors#invalid_api_key). Each message says what to fix.

There's no separate test mode: every run spends real credit. To try an input without paying for it, [get a quote](/docs/pricing#get-a-quote).

## Browse without a key

The catalog is public, so you can explore models and prices before you sign up:

```bash theme={"theme":"css-variables"}
curl https://api.tryleap.ai/v1/public/models
curl https://api.tryleap.ai/v1/public/models/black-forest-labs/flux-2-pro
```

They return the same models, prices and input schemas as `GET /v1/models`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.