Skip to content

OpenAI & Anthropic API Key Tester

Identify an AI API key's provider from its prefix (Anthropic, OpenAI, OpenRouter, Groq, Google AI, xAI and more) and check its format locally.

OpenAI & Anthropic API Key Tester

100% client-side processing

Your API key is validated entirely in your browser. Nothing is sent to any server or logged anywhere.

OpenAI, format valid

Provider detection

Provider:OpenAI
Format:Valid
Key type:Test/Development
Length:52 chars
This appears to be a test/development key. It may have limited functionality or rate limits.

Provider information

Available models:
GPT-6 AstraGPT-6.1 SolGPT-6 SolGPT-6 LunaGPT-5.6 SolGPT-5.6 TerraGPT-5.6 LunaGPT-5.5GPT-5.5 ProGPT-5.4GPT-5.4 ProGPT-5.4 Mini
Pricing:$0.10–180/million tokens

OpenClaw configuration

Add this to your OpenClaw config.json5 file:

// OpenClaw config.json5
{
  env: {
    OPENAI_API_KEY: "sk-test-EXAM..."
  }
}

Or set the environment variable: OPENAI_API_KEY

Security best practices

  • ✓Never commit API keys to version control (use .env files)
  • ✓Rotate keys regularly, especially if exposed
  • ✓Use environment variables or secret management services
  • ✓Set up usage alerts and spending limits in provider dashboards
  • ✓Use restricted keys with minimal permissions when possible

What this tool does

This tool checks whether an AI API key is well-formed and which provider issued it without sending the key anywhere: provider detection and format validation run entirely in your browser. It recognizes OpenAI, Anthropic, Google, Mistral, DeepSeek, Groq, OpenRouter, Cohere, and xAI key formats and shows each provider's current model lineup. To confirm a key is actually live, call the provider's models endpoint directly with the commands below.

Updated . Provided as is. Check the output before you rely on it in production.

How to use OpenAI & Anthropic API Key Tester

  1. 1

    Paste the key

    Paste an API key. Nothing is sent anywhere; every check runs on the key's format in your browser.

  2. 2

    Read the detection

    The tool identifies the provider from the prefix (OpenAI, Anthropic, OpenRouter, Groq, Google AI, Mistral, DeepSeek, Cohere or xAI), checks length and character set, and flags malformed keys.

  3. 3

    Get configuration snippets

    Copy the environment variable and config snippet for the detected provider.

  4. 4

    Check the key live, separately

    A format check cannot tell whether a key is active. Use the curl examples on this page to list models with the key from your own terminal.

  5. 5

    Follow the security checklist

    Rotate exposed keys, keep keys in environment variables or a secret manager, and set spending limits in the provider dashboard.

Questions and answers

What is AI API Key Tester?
An API key is the secret token an AI provider uses to authenticate requests, and each provider uses a recognizable prefix such as sk-ant- or gsk_. This tool matches a pasted key against nine providers' formats, checks its length and characters, and shows a config snippet, without sending the key anywhere.
Does AI API Key Tester store or send my data?
No. All processing happens entirely in your browser. Your API keys stay on your device — nothing is sent to any server. The validation is purely format-based, not a live API call.
Does AI API Key Tester make real API calls with my key?
No. The tool only performs local format validation and pattern matching. It never sends your key to any external service. It checks the prefix, length, and character set to identify the provider.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/ai-api-key-tester/

For automation planning, fetch the canonical contract at /api/tool/ai-api-key-tester.json.

How do I test whether an OpenAI or Anthropic API key is valid?

In two steps, and the order matters for security. First, never paste a live production key into a website that transmits it to a server — a key tester that phones home is itself a leak. This page's checks are local-only: the tool detects the provider from the key's format and validates its structure in your browser, with no network request. Second, confirm the key is live by calling the provider's own models endpoint from your terminal. A 200 response with a model list proves the key is valid and shows which models it can access; a 401 means the key is invalid or revoked.

Verify an OpenAI key and list its models

curl https://api.openai.com/v1/models \
  -H "Authorization: Bearer $OPENAI_API_KEY"

Verify an Anthropic key and list its models

curl https://api.anthropic.com/v1/models \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01"

Which provider issued this key? Prefix reference

Provider Key prefix Note
Anthropic sk-ant-api03- Test keys use sk-ant-api-test-
OpenAI sk-proj- Classic sk-, plus sk-svcacct- and sk-admin- variants
OpenRouter sk-or-v1- One key, 200+ models
Groq gsk_
Google AI AIza Gemini API keys
Mistral mistral- / mk-
DeepSeek sk- Bare sk- prefix; disambiguated from OpenAI by key length
Cohere co- / cohere-
xAI xai- Grok API keys

Prefixes as implemented in this tool's detector; providers occasionally add new key variants.

Is it safe to paste an API key into this page?

The format check runs locally and the key is never transmitted, stored, or logged. Even so, treat any key that has touched a clipboard or browser tab with care: prefer project-scoped or test keys when experimenting, and rotate any key you suspect has leaked. If a key was committed to a public repository, rotate it immediately — scanners find exposed keys within minutes.