Guides
Production integration best practices
51cowork provides the model gateway and account credit; your service still owns credential, queue, and logging governance.
Keep the Key server-side, cache models briefly, bound input and concurrency, log sanitized request IDs, and monitor Usage and balance.
- Credential
- Server Secret
- Logs
- Sanitized request_id
- Input
- Length bounds
- Cost
- Usage + balance
Security baseline
- Keep Keys out of URLs, frontend code, logs, and analytics.
- Isolate Secrets by environment and update all clients after replacement.
- Apply input length and content boundaries in the business service.
Reliability
- Set connection, read, and overall request timeouts.
- Propagate cancellation so disconnected callers do not keep spending credit.
- Only 429, temporary 5xx, and network failures receive bounded backoff.
Observability and cost
- Record a business request ID, gateway request_id, model, and status.
- Do not log prompts, full responses, or full Keys by default.
- Read Usage and balance regularly and replenish before exhaustion.
