Authentication

Updated at:

Create and use an API key for the RAG API.

The RAG API authenticates with an API key. Pass the key in the Authorization header on every request. The workspace is identified by {workspace_id} in the endpoint, in the format https://{workspace_id}.cn-beijing.maas.aliyuncs.com/.

Get an API key

  1. Open the Model Studio console, sign in with your Alibaba Cloud account, and go to the API Key page.
  2. Create a new API key, or copy an existing one.

WarningAn API key has account-level permissions. Keep it private — don't share it publicly or commit it to a code repository.

Use the API key

Pass the key in the Authorization header on every request:

Authorization: Bearer <API-Key>

Full example:

curl "$BASE_URL/api/v1/indices/rag/index/list?page_number=1&page_size=10" \
  -H "Authorization: Bearer $BAILIAN_API_KEY"

Here, $BASE_URL is https://{workspace_id}.cn-beijing.maas.aliyuncs.com, and $BAILIAN_API_KEY is your API key.

Permissions

  • Alibaba Cloud main account — can call every endpoint directly.
  • RAM sub-account — needs the AliyunBailianDataFullAccess policy and must be added to the target workspace.
  • An API key's scope is configured in the Model Studio console.

Security recommendations

  • Keep keys out of the repo — store the API key in an environment variable such as BAILIAN_API_KEY.
  • Split by application — use a separate API key per application so you can track and revoke them independently.
  • Rotate regularly — replace your API keys on a schedule to limit the impact of a leak.

ImportantWith your credentials in hand, try calling List Knowledge Bases.