🔘 What OAuth is
No OAuth, opens the browser, you log in and click "Allow". The connection is ready — without handling any keys. It's the simplest and safest method when available.
Open the browser
Hermes takes you to the provider's page.
Log in and click "Allow"
You authorize access with your account.
Connection ready
No key to store; you can revoke it whenever you want.
🗝️ What an API key is
A API key is a string of characters that lives on a server and grants access to all models from the provider. This is the method used when there’s no OAuth.
What an API key looks like (illustrative)
sk-or-v1-3f9a... ← string secreta, vive no servidor # dá acesso a todos os modelos do provedor # fonte de modelos para comparar: openrouter.ai/models
📊 Features
- •It's a secret string — treat it like a password
- •Provides broad access to the provider's models
- •Lives on a server, not in your browser
🔁 Rotate Keys
You can rotate the API key at any time. When you rotate it, the old key never works again — it’s your defense if a key leaks.
✓ When to rotate
- ✓Suspected leak
- ✓You accidentally pasted the key somewhere
- ✓Periodic security routine
✗ What NOT to forget
- ✗The old key stops working immediately
- ✗Update wherever the key was in use
- ✗Never paste the key into chat (Track 2/3)
🧭 Who uses what
Not every provider offers OAuth. Grok and ChatGPT connect via OAuth; the Claude does NOT offer OAuth — only via API key.
🔘 Via OAuth
- •Grok
- •ChatGPT
🗝️ Via API key
- •Claude (doesn't support OAuth)
- •OpenRouter and most others
Avoids frustration: don’t look for an OAuth button for Claude — it simply doesn’t exist. Use an API key.
⚙️ homes setup: the terminal workflow
In practice, the two methods meet in the command homes setup: you choose the provider, then use OAuth (reauthenticate) or paste the API key.
Illustrative flow
$ homes setup ? Escolha o provider: > OpenRouter / OpenAI / xAI / Anthropic ... ? Método: > OAuth (reauthenticate) | Colar API key # OAuth -> abre o navegador, login, Allow # API key -> cola a string (ex.: de openrouter.ai/models)
💡 Practical tip
If you get "reauthenticate," just redo OAuth — log in and click Allow again. There's no key to look for.
⚖️ The key analogy
The image that brings it all together: OAuth is the button you can take back at any time; the An API key is a key that needs to be stored and can be rotated.
🔘 OAuth = button
- ✓Nothing to store
- ✓You can "turn off" permission whenever you want
- ✓More convenient
🗝️ API key = key
- •Needs to be stored carefully
- •Can be rotated (the old one is invalidated)
- •More control, more responsibility
Summary: convenience vs. control. Both work; choose based on what the provider offers.
🛡️ Common security mistakes
Connecting models involves credentials. The most common errors have to do with how you store (or don’t store) your key.
✓ Do it
- ✓Prefer OAuth when the provider offers it
- ✓Keep the API key outside the chat (Track 2/3)
- ✓Rotate it at the first sign of a leak
✗ Never
- ✗Pasting the API key into the chat (everything is indexed)
- ✗Reusing the same key in multiple places without control
- ✗Looking for OAuth where it doesn't exist (e.g., Claude)
Quick-reference summary (illustrative)
OAuth = botão (login + Allow) -> revogável, nada para guardar API key = chave (sk-xxxx no server) -> rotacionável, guarde fora do chat
📌 Module Summary
Next Module:
1.6 — Choosing a Model