Account overview
Three read-only endpoints tell you the state of your account from code. Use them to check before a long job, to build a spending dashboard, or to give an agent a way to watch its own budget. Reading is free.
Which endpoint to call
Section titled “Which endpoint to call”| Question | Endpoint |
|---|---|
| How much balance can I spend right now? | Account balance: GET /v1/account/balance |
| How much plan quota is left, and when does it reset? | Account quota: GET /v1/account/quota |
| What did I spend, and on what? | Usage: GET /v1/usage, /v1/usage/daily and /v1/usage/log |
Which keys can read what
Section titled “Which keys can read what”| Key | Balance | Quota | Usage |
|---|---|---|---|
| Unrestricted key | Whole account | Whole account | Whole account |
| Restricted key | Refused | Refused | Only its own usage |
| Shared API key | Refused | Refused | Refused |
A restricted key is one with a model restriction, a spend cap or a token cap. A refused call returns 403 with restricted_key_not_allowed for a restricted key and shared_key_not_allowed for a shared key. To read all three, use an unrestricted key from the account itself. See Authentication and API keys.
Per-tool keys
Section titled “Per-tool keys”To give each tool its own key, use Per-tool keys: POST, GET and DELETE on /v1/account/keys. Only the key from kenari login can call them, and a revoked login key takes its per-tool keys with it.
From an MCP client
Section titled “From an MCP client”The MCP server has one tool for each question: kenari_balance, kenari_quota and kenari_usage. They follow the same rules. For a restricted key, kenari_usage is scoped to that key, and the other two are refused.