OpenAI & Anthropic API Key Tester
Identify an AI API key's provider from its prefix (Anthropic, OpenAI, OpenRouter, Groq, Google AI, xAI and more) and check its format locally.
OpenAI & Anthropic API Key Tester
100% client-side processing
OpenAI, format valid
Provider detection
Provider information
OpenClaw configuration
Add this to your OpenClaw config.json5 file:
// OpenClaw config.json5
{
env: {
OPENAI_API_KEY: "sk-test-EXAM..."
}
}Or set the environment variable: OPENAI_API_KEY
Security best practices
- ✓Never commit API keys to version control (use .env files)
- ✓Rotate keys regularly, especially if exposed
- ✓Use environment variables or secret management services
- ✓Set up usage alerts and spending limits in provider dashboards
- ✓Use restricted keys with minimal permissions when possible
What this tool does
This tool checks whether an AI API key is well-formed and which provider issued it without sending the key anywhere: provider detection and format validation run entirely in your browser. It recognizes OpenAI, Anthropic, Google, Mistral, DeepSeek, Groq, OpenRouter, Cohere, and xAI key formats and shows each provider's current model lineup. To confirm a key is actually live, call the provider's models endpoint directly with the commands below.
Updated . Provided as is. Check the output before you rely on it in production.
How to use OpenAI & Anthropic API Key Tester
- 1
Paste the key
Paste an API key. Nothing is sent anywhere; every check runs on the key's format in your browser.
- 2
Read the detection
The tool identifies the provider from the prefix (OpenAI, Anthropic, OpenRouter, Groq, Google AI, Mistral, DeepSeek, Cohere or xAI), checks length and character set, and flags malformed keys.
- 3
Get configuration snippets
Copy the environment variable and config snippet for the detected provider.
- 4
Check the key live, separately
A format check cannot tell whether a key is active. Use the curl examples on this page to list models with the key from your own terminal.
- 5
Follow the security checklist
Rotate exposed keys, keep keys in environment variables or a secret manager, and set spending limits in the provider dashboard.
Questions and answers
What is AI API Key Tester?
Does AI API Key Tester store or send my data?
Does AI API Key Tester make real API calls with my key?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/ai-api-key-tester/
For automation planning, fetch the canonical contract at /api/tool/ai-api-key-tester.json.
How do I test whether an OpenAI or Anthropic API key is valid?
In two steps, and the order matters for security. First, never paste a live production key into a website that transmits it to a server — a key tester that phones home is itself a leak. This page's checks are local-only: the tool detects the provider from the key's format and validates its structure in your browser, with no network request. Second, confirm the key is live by calling the provider's own models endpoint from your terminal. A 200 response with a model list proves the key is valid and shows which models it can access; a 401 means the key is invalid or revoked.
Verify an OpenAI key and list its models
curl https://api.openai.com/v1/models \ -H "Authorization: Bearer $OPENAI_API_KEY"
Verify an Anthropic key and list its models
curl https://api.anthropic.com/v1/models \ -H "x-api-key: $ANTHROPIC_API_KEY" \ -H "anthropic-version: 2023-06-01"
Which provider issued this key? Prefix reference
| Provider | Key prefix | Note |
|---|---|---|
| Anthropic | sk-ant-api03- | Test keys use sk-ant-api-test- |
| OpenAI | sk-proj- | Classic sk-, plus sk-svcacct- and sk-admin- variants |
| OpenRouter | sk-or-v1- | One key, 200+ models |
| Groq | gsk_ | |
| Google AI | AIza | Gemini API keys |
| Mistral | mistral- / mk- | |
| DeepSeek | sk- | Bare sk- prefix; disambiguated from OpenAI by key length |
| Cohere | co- / cohere- | |
| xAI | xai- | Grok API keys |
Prefixes as implemented in this tool's detector; providers occasionally add new key variants.
Is it safe to paste an API key into this page?
The format check runs locally and the key is never transmitted, stored, or logged. Even so, treat any key that has touched a clipboard or browser tab with care: prefer project-scoped or test keys when experimenting, and rotate any key you suspect has leaked. If a key was committed to a public repository, rotate it immediately — scanners find exposed keys within minutes.