Scenarios
A model key is the core credential for an AI gateway to securely call large model services. When enterprises/developers connect to model APIs from multiple AI vendors through an AI gateway, a critical key scenario exists: Model keys store the authentication keys (such as vendor AccessKeys or API Secrets) for each AI vendor. The gateway uses these to initiate model API calls to the vendors on behalf of the user.
To ensure the security of sensitive key information, the microservice TSF AI Gateway is deeply integrated with Tencent Cloud Key Management System (KMS), enabling encrypted storage of keys throughout their entire lifecycle. KMS uses third-party certified Hardware Security Modules (HSMs) to generate and protect keys. This ensures that no one, including Tencent Cloud, can obtain your plaintext master keys, meeting stringent compliance requirements. Through centralized management, this feature aims to enhance security controls, eliminate the risks of plaintext leakage and unauthorized access, and simplify Ops processes such as key creation, update, disablement, and deletion.
Prerequisites
If the KMS credential is used as the generation method, you need to create a credential. For details, see SSM - Quick Start. Operation Steps
Viewing Keys
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. The list page displays all created model keys, including information such as key name, type, status, and generation method. You can perform operations such as creating, editing, or deleting keys here.
5. When the key status is "Enabled", the delete operation is grayed out and unavailable. The system prompts you with "Please disable the key first".
Creating a Key
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. On the Model Key List page, click New.
5. In the Create Key window, configure the following parameters:
|
Key Name | Yes | Up to 60 characters. Supports uppercase and lowercase letters in Chinese and English, digits, and separators ("-" and "_"). Cannot start with a digit or separator. Cannot end with a separator. |
Generation Method | Yes | KMS (KMS Credential): Associate with the credential in Tencent Cloud KMS. Enter the "Credential Name" and "Credential Version". If no KMS credential exists, click "New Credential" to jump to the creation page. Custom: Manually enter the key value (the model key is the API-KEY value, and the consumer key is the credential content). |
Description | No | The identification description information for the key. Up to 200 characters can be entered. |
6. Click OK to complete the key creation. The gateway ensures the encrypted and secure storage of keys by integrating with the KMS service, if the KMS credential is selected as the generation method.
Attention:
Select KMS (KMS Credential) as the generation method. To manage KMS credentials, go to the KMS console to perform operations. When the generation method is "Custom", modification is not supported, but copying and viewing are supported. It is displayed as "***" by default to protect sensitive information.
Viewing Key Details
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. On the Model Key List page, click the ID/Name of the target key.
5. Go to the key details page. You can view the following information:
Basic Information: Includes the key name, type, status, creation time, and more.
Bound Model Resources: Displays information about the model service resources that are associated with the current key.
Editing a Key
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. On the Model Key List page, locate the target key and click Edit in its operation column. Alternatively, on the key details page, click Edit in the upper-right corner.
5. In the edit window, you can modify the key's name and description (remarks).
6. Click OK to save the modifications.
Unbinding a Key from Model Services
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. Go to the key management page and locate the target key.
5. In the Associated Model Services list, click Unbind on the right side of the target service.
6. In the confirmation pop-up window, verify the information to be unbound and click OK to complete the unbinding.
Binding a Key to Model Services
Model services and keys have a many-to-many relationship. A model service can be bound to multiple keys, and a key can also be bound to multiple model services. You can bind multiple model services to a key.
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. On the Model Key List page, click the ID/Name of the target key to go to the Details page.
5. Click Add Resource. In the Add Resource pop-up window, all available model services are listed in the Please Select Model Service area on the left. You can quickly search for them using the search box.
6. In the list on the left, select one or more model services to be bound to this key. The selected model services will appear in the Selected list on the right.
7. To remove a model service, click the × icon on the right side of its entry in the Selected list on the right. This action removes it from this group's association.
8. After making the adjustments, click OK to save the association.
Enabling/Disabling the Key
A model key takes effect only when it is enabled. This means that when a key is disabled or inactive, the AI Gateway cannot recognize or use it for any operations. Therefore, before using a key, you must confirm whether it has been correctly enabled.
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. On the Model Key List page, locate the target key and click Disable in its operation column. The key will then be in the "Disabled" state, and the AI Gateway will be unable to recognize or use it for any operations.
5. To perform the enable operation, the target key must be in the "Disabled" state. Click Enable. The key will then be in the "Enabled" state.
Deleting the Key
2. On the instance list page, click the ID of the gateway instance you want to configure to go to its basic information page.
3. In the left sidebar, click Key Management to go to the key list page.
4. On the Model Key List page, locate the target key and click Disable in its operation column. You can delete the key only after it is disabled. After the key is disabled, click Delete.
5. A dependency check will be performed before deletion:
If the key has been disassociated from all resources (for a model key, it must be disassociated from all model services), a dialog box will directly display the key information. Click OK to delete it.
If the key still has associated resources, a pop-up window will display the message "Unresolved dependencies exist" and list the specific dependency items. You must first remove all dependencies, then click Recheck. You can delete the key only after the check passes.
Key Naming Rules
Previously, key names could not end with an equal sign (=), which prevented some vendor keys ending with = from being entered under their original names. After this adjustment, key names can end with an equal sign (=), covering more vendor key naming conventions, reducing configuration failures caused by format restrictions, and improving the success rate of key configuration.
Note: The key name is used to identify and manage the key in the console and does not affect actual calls. Key naming rules: 2 to 60 characters, supporting uppercase and lowercase Chinese and English letters, digits, and separators ("-" and "_"). It cannot start with a digit or separator, or end with a separator.
Note:
KMS Credential Status Change: If you modify a credential in the Tencent Cloud KMS console, the AI Gateway will briefly continue using the cached old credential content (the default cache duration is about 5 minutes) to ensure business continuity. We recommend that you create a new version of the credential in KMS, associate the new credential in the gateway, and then delete the old API Key version to ensure the change takes effect promptly.
To increase key high availability, we recommend that you configure multiple credentials for your model service. This prevents service unavailability and potential incidents if a credential is disabled.
Synchronizing Model Keys to Instances
Centrally manage resources such as model services, model keys, consumers, consumer keys, and consumer tags to achieve "configure once, reuse across multiple instances." With this feature, you can create a model key in the Global View and sync it to multiple instances, avoiding repeated configuration across N instances.
Support for AWS AKSK Access
AWS Bedrock uses AWS Signature V4 (AKSK) for authentication, which differs significantly from the common API Key system. After you connect the AWS Bedrock model service, you can integrate Bedrock in the AI Gateway by entering the Access Key ID, Secret Access Key, and AWS Region credentials.