API
Authentication
API keys, scopes and the Authorization header.
API keys
Create and revoke keys in Settings → API Keys. Send the key with every call:
Authorization: Bearer mr_live_…
mr_live_…keys run real models and use credits.mr_test_…keys run on the mock path for free: fixture results with realistic stages, for development and CI.
fal-style clients can send Authorization: Key mr_… instead; both forms work on the API and on the fal-compatible
queue (queue.medrun.ai).
Scopes
A key carries scopes. run can be narrowed to a model glob such as angio/*.
| Scope | Allows |
|---|---|
run |
Submitting requests (optionally limited to models) |
requests:read |
Reading requests, events, results and artifacts |
files:write |
Creating uploads |
webhooks:write |
Managing webhook endpoints |
usage:read |
Reading usage and credits |
keys:write |
Managing API keys |
org:admin |
Organisation settings |
Keep keys on the server
Never ship a key in browser or mobile code. Call MedRun from your backend, or put a server-side proxy in front of it.