51cowork APIDocs
Open docs navigation

Guides

Production integration best practices

51cowork provides the model gateway and account credit; your service still owns credential, queue, and logging governance.

Quick answer

Keep the Key server-side, cache models briefly, bound input and concurrency, log sanitized request IDs, and monitor Usage and balance.

Credential
Server Secret
Logs
Sanitized request_id
Input
Length bounds
Cost
Usage + balance
01

Security baseline

  • Keep Keys out of URLs, frontend code, logs, and analytics.
  • Isolate Secrets by environment and update all clients after replacement.
  • Apply input length and content boundaries in the business service.
02

Reliability

  • Set connection, read, and overall request timeouts.
  • Propagate cancellation so disconnected callers do not keep spending credit.
  • Only 429, temporary 5xx, and network failures receive bounded backoff.
03

Observability and cost

  • Record a business request ID, gateway request_id, model, and status.
  • Do not log prompts, full responses, or full Keys by default.
  • Read Usage and balance regularly and replenish before exhaustion.