Skip to content
AI Dev Toolkit.
Esc
  • AI Token CounterCount tokens for GPT, Claude, Gemini, DeepSeek, Qwen and more.Tool
  • LLM API Cost CalculatorEstimate per-request, daily and monthly API costs.Tool
  • AI Model ComparisonCompare prices, context windows and features across models.Tool
  • AI Model Pricing PagesSpecs, real costs and cheaper alternatives for popular models.Tool
  • Context Window CheckerSee whether your text fits each model’s context window.Tool
  • Subscription vs API CalculatorFind out whether a chat plan or the API is cheaper for you.Tool
  • GPU / VRAM CalculatorCheck how much VRAM a local model needs and which GPUs fit.Tool
  • Prompt Caching CalculatorEstimate savings from prompt caching.Tool

Playground

API key checker

Check whether an OpenAI, Anthropic, Gemini, Groq, OpenRouter or Mistral API key works. It’s free, runs in your browser, and your key goes straight to the provider, never to this site.

Provider

Sent only to api.openai.com, straight from your browser, never to this site. Kept in this tab’s memory until you clear it or leave the page. How keys are handled

One free request: it lists models and uses no tokens.

Steps

How to use the API key checker

  1. Pick the provider the key came from.
  2. Paste the key. It stays in this tab’s memory and is never saved.
  3. Press “Check key”. Your browser sends one free request straight to the provider.
  4. Read the result: whether the key works, the models it can use (or OpenRouter’s credit details), and what to do if it doesn’t.
  5. Press “Clear key” when you’re done, or just close the tab.

Method

How it works

Every AI provider has a cheap way to ask “do you recognise this key?”: an endpoint that needs a valid key but doesn’t generate any text. For OpenAI, Anthropic, Google, Groq and Mistral that’s the list models endpoint; for OpenRouter it’s the current key endpoint, which also reports the key’s credit limit and usage. The checker makes exactly one of these requests, from your browser, and reads the answer. No tokens are generated, so there’s nothing to bill.

How the answer is read

A successful reply means the key is valid, and the list that comes back shows which models it can use. When the request fails, the HTTP status and the provider’s own error type decide the result:

  • Invalid (usually 401): the provider doesn’t recognise the key. It may be incomplete, revoked, expired or from another provider. Google reports a bad key as a 400 with the reason API_KEY_INVALID.
  • No access (403, or 402 and quota errors): the key is real but can’t do this, for example a restricted OpenAI key without permission to read models, a Google key limited to other APIs, or an account with no credit.
  • Rate-limited (429): the provider is throttling the key. That normally means the key itself was accepted.
  • Couldn’t connect: no answer reached the page. Browsers report blocked requests, CORS refusals and being offline in the same way, so the checker says so plainly instead of guessing.
  • Provider error (5xx): the provider had a problem, so the key couldn’t be judged.

Whatever the outcome, the provider’s own message is shown too, with your key removed from it.

What happens to your key

The key never touches this site’s server. Your browser calls the provider directly, which works because all six allow requests from web pages (Anthropic only when the request includes its anthropic-dangerous-direct-browser-access header, which the checker sends). The key is sent in a request header, never in the URL, so it can’t end up in browser history or server logs the way a ?key= parameter can. Requests carry no cookies and no referrer.

This page’s Content Security Policy lists the only addresses scripts may connect to: this site, the six provider APIs and Cloudflare’s cookie-less analytics, which never receives your key. Unlike the token counter and the Gemini playground, the checker has no “remember” option: the key lives in the page’s memory until you clear it or leave. See the privacy policy for the full details.

A safety catch for the wrong provider

Several providers use recognisable prefixes: Anthropic keys start with sk-ant-, OpenRouter keys with sk-or-, Groq keys with gsk_. If you paste a key that clearly belongs to a different provider from the one selected, the checker stops before sending anything and asks, because a key sent to the wrong company has been shown to that company. Mistral doesn’t document a key format, so its keys are never second-guessed. A key is never rejected just for its format.

What a valid result doesn’t prove

A key can be valid and still fail on real requests. OpenAI and Anthropic need prepaid credit before generation works, free tiers have daily limits, and some models are only available on higher tiers. Use the LLM cost calculator to see what your usage will cost, or try a free Gemini key in the Gemini playground.

Examples

Worked examples

The request the checker sends for each provider

ProviderRequestKey goes inWhat it shows
OpenAIGET api.openai.com/v1/modelsAuthorization: BearerModels the key’s project can use
AnthropicGET api.anthropic.com/v1/modelsx-api-key + anthropic-versionClaude models available to the key
GoogleGET generativelanguage.googleapis.com/v1beta/modelsx-goog-api-keyGemini models available to the key
GroqGET api.groq.com/openai/v1/modelsAuthorization: BearerModels on GroqCloud
OpenRouterGET openrouter.ai/api/v1/keyAuthorization: BearerKey label, credit limit, credit used, free tier or not
Mistral AIGET api.mistral.ai/v1/modelsAuthorization: BearerModels available to the workspace

Each request is documented in the provider’s API reference (linked in the sources below), checked 2026-10-11.

Get a key

Step-by-step guides for each provider, with free-tier and billing facts from their own docs: OpenAI, Anthropic, Google, Groq, OpenRouter and Mistral AI.

FAQ

Frequently asked questions

Is it safe to paste my API key here?

Your key goes from your browser straight to the provider you pick, never to this site. The page’s security policy only allows connections to the six providers’ API addresses, the key is kept in the tab’s memory (never saved, logged or put in a URL), and it’s gone when you clear it or leave. If you’d rather not trust any website, you can run the same check yourself with one curl command, shown below for OpenAI.

Does checking a key cost anything or use my quota?

No. The check lists the models your key can use (for OpenRouter, it reads the key’s own details). Neither request generates any tokens, so there’s nothing to bill. A provider may still count it as one request towards a per-minute rate limit, which is why a rate-limited key can show up as rate-limited here.

My key is valid, so why do my requests still fail?

A valid key only proves the provider recognises it. Requests can still fail if the account has no prepaid credit (OpenAI, Anthropic), you’ve hit a rate or daily limit, the model you asked for isn’t available to your account, or a restricted key lacks permission for that endpoint. The error message from the real request tells you which.

What does “couldn’t connect” mean?

Your browser couldn’t get an answer from the provider. Common causes are an ad blocker or privacy extension, a VPN, a company firewall, being offline, or the provider’s API being down. Browsers deliberately hide the exact reason from web pages, so the checker can’t tell these apart. Try another network or turn extensions off for this page.

Why won’t it send my key to the provider I picked?

If the key clearly starts with another provider’s prefix (for example sk-ant- while OpenAI is selected), the checker stops and asks first, because sending a key to the wrong company would expose it to them. You can switch provider with one click or check anyway.

How do I check an OpenAI API key from the command line?

Ask for the model list with the key: curl https://api.openai.com/v1/models -H "Authorization: Bearer $OPENAI_API_KEY". A list of models means the key works; a 401 with invalid_api_key means OpenAI doesn’t recognise it. It’s the same request this checker sends, and it generates no tokens. Each provider’s key guide on this site shows a curl request for that API.

Can it tell how much credit I have left?

Only for OpenRouter, whose key endpoint reports the key’s credit limit, how much it has used and whether the account is on the free tier. OpenAI, Anthropic, Google, Groq and Mistral don’t expose balances to a normal API key, so check the billing page in their consoles.