Skip to content

Authentication

Quake AI uses OpenStack Keystone for identity and authentication. Every API request must include a valid token in the X-Auth-Token header.

Get a token

The fastest way to get a token is through the OpenStack CLI or the Quake AI console.

Via CLI

# Issue a token (requires openrc sourced or clouds.yaml configured)
export TOKEN=$(openstack token issue -f value -c id)
export PROJECT_ID=$(openstack project show <project-name> -f value -c id)

# Verify
echo $TOKEN

Via console

  1. Navigate to API → API Endpoints → Get Token in the Quake AI console.
  2. Copy the token.
  3. The token is valid for 24 hours.

See Console token management for the full console walkthrough.

Use the token

Include the token in every request as the X-Auth-Token header:

curl -s \
  -H "X-Auth-Token: $TOKEN" \
  https://compute.us-east-1.rumble.cloud/v2.1/servers

Application credentials

For long-lived automation (CI/CD, scripts, SDK clients), use application credentials instead of personal tokens. Application credentials are scoped to a project and can be restricted to specific roles.

# Create an application credential
openstack application credential create my-ci-credential \
  --description "CI pipeline access"

# Authenticate with it
export OS_AUTH_TYPE=v3applicationcredential
export OS_APPLICATION_CREDENTIAL_ID=<credential-id>
export OS_APPLICATION_CREDENTIAL_SECRET=<credential-secret>
export TOKEN=$(openstack token issue -f value -c id)
Security note: Application credential secrets are shown only once at creation time. Store them in a secrets manager, not in source control.

Token scoping

Tokens are scoped to a project (tenant). Most API endpoints require the project ID in the URL path. Get your project ID with:

openstack project show <project-name> -f value -c id

Token expiration and refresh

Keystone tokens expire after 24 hours. The X-Subject-Token response header from a token issue request contains the expiration timestamp. For long-running scripts, re-issue tokens periodically.

Common errors

StatusMeaningFix
401 UnauthorizedToken is missing, expired, or invalidRe-issue the token
403 ForbiddenToken is valid but lacks the required role for this actionCheck project membership and role assignments
404 Not FoundCorrect token but wrong project ID in the URLVerify the project ID matches the token scope