Authorization header. WebSocket clients that cannot set headers may instead pass ?rime_apikey=YOUR_API_KEY on the connection URL, but this puts the key in URLs and proxy logs, so prefer a server-side bridge that sets the header.
Get an API key
- Sign in to the Rime dashboard.
- In the Rime dashboard, open API Tokens.
- Create a token and copy its value.
Use the token
This request authenticates with a bearer token and saves the MP3 response tohello.mp3:
hello.mp3. If it isn’t, --fail stops curl with a 401 instead of saving the error text as the file.
Use the same header for the HTTP, WebSocket, metadata, and utility endpoints.
CLI authentication
Therime CLI manages the key locally. Run rime login once, and the CLI stores the key at ~/.rime/rime.toml. You can also set it with the RIME_CLI_API_KEY environment variable.
On-prem authentication
Caller authentication depends on the deployment. A standalone licensed engine doesn’t authenticate callers, so your gateway must. ItsRIME_API_KEY only authenticates the engine’s usage reports to Rime. In an existing API/model pair, the API service accepts the same Authorization: Bearer … header, or you can configure RIME_API_KEY for the deployment so callers don’t need to send it. See the on-prem quickstart for details.
Common auth errors
If your request fails authentication, the API returns401 Unauthorized with a short plain-text body explaining why:
Always send the header as
Authorization: Bearer <token> (capital B). The token alone, without Bearer, is rejected.

