All Products
Search
Document Center

OpenSearch:Authentication

Last Updated:Apr 01, 2026

AI Open Search Platform verifies your identity or permissions every time you call its services via API operations or SDKs. Two credential types are supported: API keys (recommended) and AccessKey pairs.

Choose an authentication method

API keyAccessKey pair
Issued byAI Open Search PlatformAlibaba Cloud
ScopeWorkspace-specificScoped by Resource Access Management (RAM) permissions
RevocableYes — disable or delete in the consoleYes — via RAM console

Start with an API key if you are building within a single workspace. Use an AccessKey pair with a dedicated RAM user if you need fine-grained, least-privilege access across services.

Use an API key (recommended)

An API key is a workspace-scoped credential issued by AI Open Search Platform. If a RAM user is authorized to use an enabled API key in a workspace and the API key is specified in the code, the RAM user can call all services within that workspace without additional authorization.

Get an API key

Log in to the AI Open Search Platform console and create and manage API keys in your workspace. To authorize a RAM user to use an API key, see Create RAM users and grant permissions.

Use the API key in your code

Pass the API key as a request header or when initializing your SDK client. Store the key in an environment variable rather than hard-coding it.

Important

API calls must originate from a server — not from a client such as a browser, mobile application, or mini program. Client-side calls expose the API key in the request.

The following examples show how to pass the API key using environment variables:

# Python example
import os

api_key = os.environ.get("OPENSEARCH_API_KEY")
# Pass api_key when initializing your AI Open Search Platform client
// Java example
String apiKey = System.getenv("OPENSEARCH_API_KEY");
// Pass apiKey when initializing your AI Open Search Platform client

Revoke a compromised API key

If you suspect a leak, log in to the AI Open Search Platform console, disable the API key, then delete it. A disabled API key cannot be used to call any API operations.

Security checklist

  • Never share or commit your API key to source control.

  • Always initiate API calls from a server, not from a client.

  • Disable and delete the API key immediately if a leak is suspected.

Use an AccessKey pair

An AccessKey pair is a permanent access credential provided by Alibaba Cloud, consisting of an AccessKey ID and an AccessKey secret. It is not used to log in to Alibaba Cloud service consoles — it is used programmatically via APIs, CLI, SDKs, and Terraform. Each request is signed using the AccessKey pair; the signature verifies both your identity and the validity of the request.

Get an AccessKey pair

Create a dedicated RAM user for API access, generate an AccessKey pair for that user, and grant the user only the permissions it needs (principle of least privilege). See Create RAM users and grant permissions.

Use the AccessKey pair in your code

Store the AccessKey ID and AccessKey secret as environment variables, then reference them at runtime:

# Python example
import os

access_key_id = os.environ.get("ALIBABA_CLOUD_ACCESS_KEY_ID")
access_key_secret = os.environ.get("ALIBABA_CLOUD_ACCESS_KEY_SECRET")
# Pass access_key_id and access_key_secret when initializing your AI Open Search Platform client
// Java example
String accessKeyId = System.getenv("ALIBABA_CLOUD_ACCESS_KEY_ID");
String accessKeySecret = System.getenv("ALIBABA_CLOUD_ACCESS_KEY_SECRET");
// Pass accessKeyId and accessKeySecret when initializing your AI Open Search Platform client

For steps to configure environment variables on Linux, macOS, and Windows, see Configure environment variables in Linux, macOS, and Windows.

Security checklist

  • Never hard-code an AccessKey ID or AccessKey secret in source code or configuration files.

  • Use environment variables or a secrets manager to inject credentials at runtime.

  • Grant only the minimum permissions required for the RAM user associated with the AccessKey pair.

What's next