Keys
An API key is stored only as a sha256 hash. We cannot show it to you again, and a database dump cannot be used to call the API.
An API key is stored only as a sha256 hash. We cannot show it to you again, and a database dump cannot be used to call the API.
Prompts and answers are never published. Only a salted hash goes to the ledger, and the salt stays with us so a short prompt cannot be guessed from the public log.
Identity is Zanii ID: MFA, passkeys and recovery live there. Issuing or revoking a key needs a strong sign-in less than ten minutes old.
Every amount is an integer. A call is refused before the model is asked when the balance cannot cover it, and a retried request is never charged twice.
Report a security issue to info@zanii.agency with 'security' in the subject line.