# API keys (/llm-gateway/api-keys)



## Deployments and workspaces [#deployments-and-workspaces]

You do not create gateway keys by hand. Crucible issues a separate key for each full deployment, lite deployment, and workspace, and sets `LLM_GATEWAY_API_KEY` and `LLM_GATEWAY_ENDPOINT` in its backend environment before the runtime starts. The key is a backend secret, so it never reaches frontend code.

```mermaid
flowchart TD
  C[Crucible] --> F[Full deployment]
  C --> L[Lite deployment]
  C --> W[Workspace]
  C --> D[Local developer]
  F -->|own key| G[LLM Gateway]
  L -->|own key| G
  W -->|own key| G
  D -->|own key| G
```

## Local development [#local-development]

Open the project in Crucible, choose **Work locally**, and copy the listed backend file's values into the matching file on your machine. That file includes `LLM_GATEWAY_API_KEY` and `LLM_GATEWAY_ENDPOINT`. See [Work locally](/work-locally/) for the full setup.

<Accordions>
  <Accordion title="Under the hood: key issuance">
    The `llm_gateway` standard integration mints each key through the gateway's management API when Crucible provisions a target: a full deployment, a lite deployment or workspace, or one person's local-development access. Each key is scoped to that target, so Crucible can revoke it without touching the others.
  </Accordion>
</Accordions>
