Skip to content

API

Authentication

API keys, scopes and the Authorization header.

API keys

Create and revoke keys in Settings → API Keys. Send the key with every call:

Authorization: Bearer mr_live_…
  • mr_live_… keys run real models and use credits.
  • mr_test_… keys run on the mock path for free: fixture results with realistic stages, for development and CI.

fal-style clients can send Authorization: Key mr_… instead; both forms work on the API and on the fal-compatible queue (queue.medrun.ai).

Scopes

A key carries scopes. run can be narrowed to a model glob such as angio/*.

Scope Allows
run Submitting requests (optionally limited to models)
requests:read Reading requests, events, results and artifacts
files:write Creating uploads
webhooks:write Managing webhook endpoints
usage:read Reading usage and credits
keys:write Managing API keys
org:admin Organisation settings

Keep keys on the server

Never ship a key in browser or mobile code. Call MedRun from your backend, or put a server-side proxy in front of it.