Playground
API key checker
Check whether an OpenAI, Anthropic, Gemini, Groq, OpenRouter or Mistral API key works. It’s free, runs in your browser, and your key goes straight to the provider, never to this site.
Steps
How to use the API key checker
- Pick the provider the key came from.
- Paste the key. It stays in this tab’s memory and is never saved.
- Press “Check key”. Your browser sends one free request straight to the provider.
- Read the result: whether the key works, the models it can use (or OpenRouter’s credit details), and what to do if it doesn’t.
- Press “Clear key” when you’re done, or just close the tab.
Method
How it works
Every AI provider has a cheap way to ask “do you recognise this key?”: an endpoint that needs a valid key but doesn’t generate any text. For OpenAI, Anthropic, Google, Groq and Mistral that’s the list models endpoint; for OpenRouter it’s the current key endpoint, which also reports the key’s credit limit and usage. The checker makes exactly one of these requests, from your browser, and reads the answer. No tokens are generated, so there’s nothing to bill.
How the answer is read
A successful reply means the key is valid, and the list that comes back shows which models it can use. When the request fails, the HTTP status and the provider’s own error type decide the result:
- Invalid (usually 401): the provider doesn’t recognise the key. It may be incomplete, revoked, expired or from another provider. Google reports a bad key as a 400 with the reason
API_KEY_INVALID. - No access (403, or 402 and quota errors): the key is real but can’t do this, for example a restricted OpenAI key without permission to read models, a Google key limited to other APIs, or an account with no credit.
- Rate-limited (429): the provider is throttling the key. That normally means the key itself was accepted.
- Couldn’t connect: no answer reached the page. Browsers report blocked requests, CORS refusals and being offline in the same way, so the checker says so plainly instead of guessing.
- Provider error (5xx): the provider had a problem, so the key couldn’t be judged.
Whatever the outcome, the provider’s own message is shown too, with your key removed from it.
What happens to your key
The key never touches this site’s server. Your browser calls the provider directly, which works because all six allow requests from web pages (Anthropic only when the request includes its anthropic-dangerous-direct-browser-access header, which the checker sends). The key is sent in a request header, never in the URL, so it can’t end up in browser history or server logs the way a ?key= parameter can. Requests carry no cookies and no referrer.
This page’s Content Security Policy lists the only addresses scripts may connect to: this site, the six provider APIs and Cloudflare’s cookie-less analytics, which never receives your key. Unlike the token counter and the Gemini playground, the checker has no “remember” option: the key lives in the page’s memory until you clear it or leave. See the privacy policy for the full details.
A safety catch for the wrong provider
Several providers use recognisable prefixes: Anthropic keys start with sk-ant-, OpenRouter keys with sk-or-, Groq keys with gsk_. If you paste a key that clearly belongs to a different provider from the one selected, the checker stops before sending anything and asks, because a key sent to the wrong company has been shown to that company. Mistral doesn’t document a key format, so its keys are never second-guessed. A key is never rejected just for its format.
What a valid result doesn’t prove
A key can be valid and still fail on real requests. OpenAI and Anthropic need prepaid credit before generation works, free tiers have daily limits, and some models are only available on higher tiers. Use the LLM cost calculator to see what your usage will cost, or try a free Gemini key in the Gemini playground.
Examples
Worked examples
The request the checker sends for each provider
| Provider | Request | Key goes in | What it shows |
|---|---|---|---|
| OpenAI | GET api.openai.com/v1/models | Authorization: Bearer | Models the key’s project can use |
| Anthropic | GET api.anthropic.com/v1/models | x-api-key + anthropic-version | Claude models available to the key |
| GET generativelanguage.googleapis.com/v1beta/models | x-goog-api-key | Gemini models available to the key | |
| Groq | GET api.groq.com/openai/v1/models | Authorization: Bearer | Models on GroqCloud |
| OpenRouter | GET openrouter.ai/api/v1/key | Authorization: Bearer | Key label, credit limit, credit used, free tier or not |
| Mistral AI | GET api.mistral.ai/v1/models | Authorization: Bearer | Models available to the workspace |
Each request is documented in the provider’s API reference (linked in the sources below), checked 2026-10-11.
Get a key
Step-by-step guides for each provider, with free-tier and billing facts from their own docs: OpenAI, Anthropic, Google, Groq, OpenRouter and Mistral AI.
FAQ
Frequently asked questions
Is it safe to paste my API key here?
Your key goes from your browser straight to the provider you pick, never to this site. The page’s security policy only allows connections to the six providers’ API addresses, the key is kept in the tab’s memory (never saved, logged or put in a URL), and it’s gone when you clear it or leave. If you’d rather not trust any website, you can run the same check yourself with one curl command, shown below for OpenAI.
Does checking a key cost anything or use my quota?
No. The check lists the models your key can use (for OpenRouter, it reads the key’s own details). Neither request generates any tokens, so there’s nothing to bill. A provider may still count it as one request towards a per-minute rate limit, which is why a rate-limited key can show up as rate-limited here.
My key is valid, so why do my requests still fail?
A valid key only proves the provider recognises it. Requests can still fail if the account has no prepaid credit (OpenAI, Anthropic), you’ve hit a rate or daily limit, the model you asked for isn’t available to your account, or a restricted key lacks permission for that endpoint. The error message from the real request tells you which.
What does “couldn’t connect” mean?
Your browser couldn’t get an answer from the provider. Common causes are an ad blocker or privacy extension, a VPN, a company firewall, being offline, or the provider’s API being down. Browsers deliberately hide the exact reason from web pages, so the checker can’t tell these apart. Try another network or turn extensions off for this page.
Why won’t it send my key to the provider I picked?
If the key clearly starts with another provider’s prefix (for example sk-ant- while OpenAI is selected), the checker stops and asks first, because sending a key to the wrong company would expose it to them. You can switch provider with one click or check anyway.
How do I check an OpenAI API key from the command line?
Ask for the model list with the key: curl https://api.openai.com/v1/models -H "Authorization: Bearer $OPENAI_API_KEY". A list of models means the key works; a 401 with invalid_api_key means OpenAI doesn’t recognise it. It’s the same request this checker sends, and it generates no tokens. Each provider’s key guide on this site shows a curl request for that API.
Can it tell how much credit I have left?
Only for OpenRouter, whose key endpoint reports the key’s credit limit, how much it has used and whether the account is on the free tier. OpenAI, Anthropic, Google, Groq and Mistral don’t expose balances to a normal API key, so check the billing page in their consoles.
Related
Related tools
- How to get a free Gemini API keyFree key from Google AI Studio, no card needed.
- How to get a Groq API keyFree plan with fast open models.
- Gemini API PlaygroundChat with free Gemini models using your key.
- AI Token CounterExact token counts, official counts for Claude and Gemini.
- LLM API Cost CalculatorWhat your requests will cost per month.