The moment a second person uses your local model, you have an access-control problem. Most setups solve it by pasting the same key into a chat.

Why a shared key goes wrong

One key for everyone means you cannot tell who is calling, you cannot cut off one person without cutting off all of them, and a leak means rotating the key for the whole team. When a job hammers the model at 3 a.m., nobody knows whose it was.

Give each person their own token

With Tokmine, every request needs a consumer token, and there are no open endpoints. Signed-in callers use their own account token, so usage is attributable to a person. Tokens are stored hashed, shown once, compared in constant time and never logged.

What you get

  • Attribution. Usage counts per day, on your dashboard.
  • Revocation. Remove one person without touching anyone else.
  • Smaller blast radius. A leaked token is one person's problem.

Nothing extra exposed

The CLI opens an outbound connection, so your machine accepts no inbound traffic from the internet. Callers cannot choose a host or an arbitrary path, only the allow-listed API paths of the model servers you exposed. Read the details on the security page.

Practical habits

Keep tokens in environment variables such as TOKMINE_TOKEN and out of version control. Give each person, and each CI job, a separate token. Review the dashboard now and then for anything unexpected.

Try it

Create an account, run tokmine login, and invite the people who need the model. Start from the account docs.