_private_function()). Authenticate using the JWT token from the API Keys section of the dashboard. Endpoints require this token only when cerebrium.toml sets disable_auth = false. Authentication is disabled by default.
Managing API keys
Create and manage keys in the API Keys section of the dashboard, or with the Create API Key endpoint. Cerebrium returns the secret value once, at creation time.- Expiration: Set an optional expiration date (
YYYY-MM-DD) when creating a key. A key without an expiration date never expires. - Rotation: Cerebrium does not rotate keys automatically. To rotate a key, create a new key, update your clients to use it, then delete the old key.
- Deletion: Deleting a key is permanent. Requests using the deleted key start failing within a few seconds, and you cannot recover the key. Only project owners can delete keys. To remove a key that belongs to a service account, delete the service account.
Request format
The POST request follows the structure below, where{function} is the name of the function to invoke. This example calls predict() from main.py.
Regioned hostnames such as
https://api.aws.us-east-1.cerebrium.ai continue
to work. Requests to these hostnames are proxied to the global router, which
can add latency. Use https://api.cerebrium.ai for the lowest-latency path.Response format
Responses follow this format:Status codes
200→ the function completed successfully401/403→ authentication or authorization failed404→ the app or function path could not be found5xx→ either your app raised an exception or the platform could not complete the request
422 or 404, include a status_code field in the JSON response from main.py.
When debugging a failed request, check the HTTP status code and the app logs
in the Cerebrium dashboard. Inspecting the request payload, logs, and
run_id
together speeds up diagnosis.