Skip to main content
Every request to the Rime API requires a bearer token. Send it in the Authorization header. WebSocket clients that cannot set headers may instead pass ?rime_apikey=YOUR_API_KEY on the connection URL, but this puts the key in URLs and proxy logs, so prefer a server-side bridge that sets the header.

Get an API key

An API key can synthesize speech against your account. Keep it on the server and treat it like a password.
  1. Sign in to the Rime dashboard.
  2. In the Rime dashboard, open API Tokens.
  3. Create a token and copy its value.

Use the token

This request authenticates with a bearer token and saves the MP3 response to hello.mp3:
If the key is accepted, you’ll hear “hello” when you play hello.mp3. If it isn’t, --fail stops curl with a 401 instead of saving the error text as the file. Use the same header for the HTTP, WebSocket, metadata, and utility endpoints.

CLI authentication

The rime CLI manages the key locally. Run rime login once, and the CLI stores the key at ~/.rime/rime.toml. You can also set it with the RIME_CLI_API_KEY environment variable.

On-prem authentication

Caller authentication depends on the deployment. A standalone licensed engine doesn’t authenticate callers, so your gateway must. Its RIME_API_KEY only authenticates the engine’s usage reports to Rime. In an existing API/model pair, the API service accepts the same Authorization: Bearer … header, or you can configure RIME_API_KEY for the deployment so callers don’t need to send it. See the on-prem quickstart for details.

Common auth errors

If your request fails authentication, the API returns 401 Unauthorized with a short plain-text body explaining why: Always send the header as Authorization: Bearer <token> (capital B). The token alone, without Bearer, is rejected.