How to get a Kling AI API key and authenticate requests
Create a Kling AI API key in the developer console, copy it once, and send it as a Bearer token. Legacy endpoints use an Access Key JWT instead.

To get a Kling AI API key, sign in to Kling's developer console at kling.ai/dev/api-key with your Kling AI account, click “+ Create a new API Key”, name the key and copy it: Kling shows it only once. Send it on every request as Authorization: Bearer <key>. Kling's quick start also has you buy a video or image resource package before calling.
Every Kling step below comes from Kling's own API docs, read on 2026-09-28 and listed under Sources; Kling's console is its own product, so menus may change. The last section covers calling Kling 3.0 with a Sume key instead, from Sume's Authentication docs.
What are the steps, from account to first call?
Kling's Quick Start lists six steps:
- Open the Kling AI API platform at
kling.ai/dev. - Buy a video or image generation resource package. Kling also offers a trial package for integration testing.
- Log in to the developer console at
kling.ai/dev/api-keywith your email; it is the same account as the Kling AI web app. - Create and name an API key, then copy it. It is shown once, so store it securely.
- Call the API at
https://api-singapore.klingai.com. - Watch call volume and package use in the console.
How do I send the Kling API key?
Put it in the Authorization header as Bearer, a space, then the key. Kling says a leaked key can lead to “theft of call limits” and recommends keeping it in an environment variable (Authentication). The domain moved from api.klingai.com to api-singapore.klingai.com, which Kling describes as the endpoint for servers outside China. A minimal Kling 3.0 call (text to video):
curl https://api-singapore.klingai.com/text-to-video/kling-3.0 \
-H "Authorization: Bearer $KLING_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"prompt": "A red kite rising over a windy beach",
"settings": { "duration": 5, "aspect_ratio": "16:9" }
}'What are the Kling Access Key and Secret Key for?
Older endpoints use them. Kling tells the two designs apart by where the model goes: the model version in the path is the new design, and a model_name parameter is the legacy one. For legacy endpoints you get an Access Key and a Secret Key, and your server signs a JWT (RFC 7519, HS256) for each request, with the Access Key as iss; Kling's example sets exp 1,800 seconds ahead and nbf 5 seconds back. You then send that token as Authorization: Bearer <token> (Authentication). Sign it on a server, since the Secret Key is the signing key.
Why does Kling return 401 or 429?
Most key problems show up as an HTTP status plus a Kling service code in the body:
| HTTP | Service code | Meaning |
|---|---|---|
| 401 | 1000 | Authentication failed: check the Authorization header |
| 401 | 1001 | Authorization is empty |
| 401 | 1002 | Authorization is invalid |
| 401 | 1003 / 1004 | Authorization not yet valid / expired: check the token's validity window |
| 403 | 1103 | No access to the requested API or model |
| 429 | 1102 | Resource pack exhausted or expired (prepaid) |
| 429 | 1303 | Concurrency or QPS over the resource package limit |
How long do Kling results stay available?
Kling's task query docs say generated results “will be cleared after 30 days”, so save the files you want to keep (text to video). Where to store API keys covers keeping the key itself out of client code.
Do I need a Kling key to use Kling 3.0 through Sume?
No. On Sume today, Kling 3.0 is kling-3 on POST /v1/videos (Video generation), called with your Sume workspace API key instead of a Kling key. Like a Kling key, it belongs on your server, not in frontend JavaScript or mobile apps (Authentication). Kling 3.0 API covers that request, and Sume vs Kling compares the two billing models.
Sources
Related posts
More in Developers
- How to get a public URL for an image an API can fetch
Host the image where anyone can fetch it over HTTPS without a login: a public storage object, a public bucket URL, or your own site. Then test it.
- How to test an MCP server: Inspector, Postman, or curl
Test an MCP server with the MCP Inspector: connect, sign in or add an auth header, list tools, and call a read-only one. Postman and curl work too.
- HTTP 202 vs 201: created now, or accepted for later?
Return 201 Created when the resource exists by the time you respond, and 202 Accepted when the work will finish later. How 200, 201 and 202 differ.
- httpx timeout: the 5-second default and slow AI API calls
httpx times out after 5 seconds of network inactivity by default. How to set connect, read, write and pool timeouts for slow AI API calls.
Written by Sume