Hmbown/CodeWhale · error

DeepSeek API key not found. 1. Get a key: …

Error message

DeepSeek API key not found.

1. Get a key:  https://platform.deepseek.com/api_keys
2. Save it (works in every folder, no OS prompts):
       codewhale auth set --provider deepseek

Alternatives:
  • export DEEPSEEK_API_KEY=<your-key>      (current shell only;
    also note: zsh users — exports in ~/.zshrc only reach interactive
    shells, prefer ~/.zshenv for everything)
  • api_key = "<your-key>"  in ~/.codewhale/config.toml
  • already configured DeepSeek Harness? grant read-only access:
       codewhale auth external-consent --provider deepseek --mode read-only

What it means

DeepSeek (and DeepSeek CN) routes require a DeepSeek platform API key. When none is found in overrides, the DEEPSEEK_API_KEY env var, config.toml, the secret store, or an external-consent grant from DeepSeek Harness, the library fails before sending a request and lists every way to supply the key.

Solutions

  1. Get a key at https://platform.deepseek.com/api_keys, then run: codewhale auth set --provider deepseek
  2. Export DEEPSEEK_API_KEY=<your-key> (zsh: put the export in ~/.zshenv so non-interactive shells see it).
  3. Add api_key = "<your-key>" under [providers.deepseek] in ~/.codewhale/config.toml.
  4. If DeepSeek Harness is already configured, grant read-only access: codewhale auth external-consent --provider deepseek --mode read-only.

Example fix

// before (in ~/.zshrc — invisible to non-interactive shells)
export DEEPSEEK_API_KEY=sk-...

// after (in ~/.zshenv)
export DEEPSEEK_API_KEY=sk-...
Defensive patterns

Strategy: validation

Validate before calling

std::env::var("DEEPSEEK_API_KEY")
    .ok()
    .filter(|k| !k.trim().is_empty())
    .ok_or_else(|| "DEEPSEEK_API_KEY missing; run codewhale auth set --provider deepseek".to_string())?;

Type guard

fn deepseek_key_ready(env_val: Option<&str>) -> bool {
    env_val.map(|k| k.starts_with("sk-")).unwrap_or(false)
}

Try / catch

match result {
    Err(e) if e.to_string().contains("DeepSeek API key not found") => {
        eprintln!("export DEEPSEEK_API_KEY=... (put exports in ~/.zshenv on zsh)");
    }
    other => other?,
}

Prevention

When it happens

Trigger: Provider resolves to ApiProvider::Deepseek or ApiProvider::DeepseekCN and no credential is present in --api-key override, DEEPSEEK_API_KEY, [providers.deepseek] api_key/api_key_env, or stored auth.

Common situations: Fresh setup; zsh users who exported DEEPSEEK_API_KEY in ~/.zshrc so non-interactive/TUI sessions never see it; rotating keys on the DeepSeek platform and deleting the stored one.

Understand the failure class

Background: "API key is required" / "API key not found" / "No API key was set": the missing-api-key error family across 16 libraries — this error's family across 16 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/35f65405b6158319. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/config.rs:7337

        match provider {
            ApiProvider::Codewhale => anyhow::bail!(
                "Codewhale API key not found, so no request was sent.\n\
                 \n\
                 The Codewhale API authenticates every model with one account \
                 API key carrying the `models:infer` scope.\n\
                 \n\
                 1. Create one and save it on this machine:\n\
                        codewhale account api-keys create --name <name> --scope models:infer --use\n\
                 2. Or export it for this shell:\n\
                        export CODEWHALE_API_KEY=cwc_key_...\n\
                 \n\
                 You can also create a key at {} and put it in \
                 [providers.codewhale] api_key (or api_key_env).",
                provider
                    .credential_url()
                    .unwrap_or("https://app.codewhale.net/settings?section=api")
            ),
            ApiProvider::Deepseek | ApiProvider::DeepseekCN => anyhow::bail!(
                "DeepSeek API key not found.\n\
                 \n\
                 1. Get a key:  https://platform.deepseek.com/api_keys\n\
                 2. Save it (works in every folder, no OS prompts):\n\
                        codewhale auth set --provider deepseek\n\
                 \n\
                 Alternatives:\n\
                   • export DEEPSEEK_API_KEY=<your-key>      (current shell only;\n\
                     also note: zsh users — exports in ~/.zshrc only reach interactive\n\
                     shells, prefer ~/.zshenv for everything)\n\
                   • api_key = \"<your-key>\"  in ~/.codewhale/config.toml\n\
                   • already configured DeepSeek Harness? grant read-only access:\n\
                        codewhale auth external-consent --provider deepseek --mode read-only"
            ),
            ApiProvider::SiliconflowCn => anyhow::bail!(
                "SiliconFlow China API key not found. Get a key: {}. Run 'codewhale auth set --provider siliconflow-CN', \
                 set {}, or add [{}] api_key in ~/.codewhale/config.toml. \
                 [providers.siliconflow] remains a fallback when the CN table omits api_key.",

View on GitHub (pinned to 73e0f67d83)