Manage keys and sessions
Use a custom signer, hold the result key explicitly, reuse session tokens and choose the result gateway.
By default, vorq.Client() needs one secret, VORQ_WALLET_KEY, and derives everything else
from it. This page covers the cases where you want something different.
Keep the wallet key in a KMS or remote signer
Pass any object that implements the Signer protocol:
client = vorq.Client(signer=my_kms_signer, cipher=vorq.SealedBoxCipher())The signer is the root credential: it signs the session handshake, orders, payment
authorizations and cancels. A custom signer can't derive the result key, so also pass a
cipher=, or set VORQ_CIPHER_KEY, which such a client reads automatically. Without a cipher,
submit raises ValidationError.
Hold the result key explicitly
A client built on VORQ_WALLET_KEY derives its result key from the wallet. To keep a separate
Curve25519 key instead, for example so a reader process can open results without the wallet:
# generate a 32-byte Curve25519 private key once, and keep it as VORQ_CIPHER_KEY
export VORQ_CIPHER_KEY=$(python -c "import secrets; print(secrets.token_hex(32))")client = vorq.Client(cipher=vorq.SealedBoxCipher()) # reads $VORQ_CIPHER_KEYAn explicit cipher= always wins over the derived key. Results sealed to one key open only with
that key: when you switch between the derived key and an explicit one, keep the old key until
its jobs have settled.
Reuse a session token
vorq.mint_session_token()runs the wallet handshake once, synchronously, and returns avorq_sess_…token. Use it to call routes that carry no prompt, such asGET /v1/models, from your own HTTP code.vorq.Client.from_session_token(token, ...)builds a client on an existing token. Without asigner=, the token is used as-is and never rotated, and the client can read jobs but can't submit or cancel.
See Persist and resume jobs for a read-only process.
Choose where result bytes are read from
A settled job names its result by content address. The client reads those bytes from a storage gateway, not from the coordinator, in this order of precedence:
vorq.Client(gateway="https://ipfs.filebase.io");- the
VORQ_PIN_GATEWAYenvironment variable; - the built-in public gateway,
https://ipfs.filebase.io.
An empty string at either of the first two levels disables the gateway, and reading a result
then raises VorqError. See Reading results.