How to Set the API Key for Your Vector Database in Cognee: 3 Methods Explained

Use cognee.config.set_vector_db_key("your-api-key") to set your vector database API key in memory, or use cognee.config.set_vector_db_config() to batch-update settings from a dictionary.

Cognee is an open-source knowledge graph framework that supports multiple vector database backends including PGVector, ChromaDB, and Neptune Analytics. To authenticate with these services, you must set the API key for your vector database in Cognee before initializing the vector engine. This guide shows you exactly how to configure credentials using the official configuration API based on the actual source code implementation.

Where Cognee Stores Vector Database Credentials

Cognee maintains a singleton VectorDBConfig object that holds the vector_db_key attribute. According to the source code in cognee/infrastructure/databases/vector/models/VectorConfig.py, this Pydantic model defines the shape of all vector database settings. The configuration is accessed globally via get_vectordb_config() from cognee/infrastructure/databases/vector/__init__.py, ensuring consistency across pipelines, CLI commands, and the MCP server.

The fastest way to set your API key is using the dedicated setter method in cognee/api/v1/config/config.py (lines 78-81).

import cognee

# Set the API key for the vector store

cognee.config.set_vector_db_key("sk-my-very-secret-key")

This method updates the in-memory vector_db_key attribute of the global vector database configuration. The change takes effect immediately for any subsequent vector engine initialization.

Method 2: Dictionary-Based Configuration (Batch Updates)

When loading settings from JSON or YAML files, use set_vector_db_config() to validate and merge multiple settings at once. This method is implemented in cognee/api/v1/config/config.py (lines 71-75) and validates each key against the VectorDBConfig model.

import json
import cognee

# Load configuration from a file

with open("vector_config.json") as f:
    cfg = json.load(f)  # {"vector_db_provider": "chromadb", "vector_db_key": "sk-123"}

cognee.config.set_vector_db_config(cfg)

If you pass an invalid attribute name, Cognee raises InvalidConfigAttributeError, preventing typos from causing silent failures.

Method 3: Persistent Configuration (Production Deployments)

For scenarios requiring persistence, use the save_vector_db_config helper from cognee/modules/settings/save_vector_db_config.py (lines 12-20). This approach writes the configuration to the underlying persistence layer while validating that the key is non-empty and not masked.

from cognee.modules.settings.save_vector_db_config import VectorDBConfig, save_vector_db_config

# Build a complete configuration object

cfg = VectorDBConfig(
    url="https://my-vector-db.example.com",
    api_key="sk-my-very-secret-key",
    provider="chromadb"
)

# Persist the configuration

await save_vector_db_config(cfg)

The helper checks that the key is not the masked placeholder "*****" before saving, ensuring you don't accidentally persist a redacted value.

How the API Key Flows Through Cognee's Architecture

Understanding the data flow helps debug authentication issues:

  1. Startup: Cognee instantiates a singleton VectorDBConfig object.
  2. Configuration: You set the vector_db_key using one of the three methods above, mutating the singleton.
  3. Adapter Creation: When code calls get_vector_engine(), the vector adapter (PGVector, ChromaDB, or Neptune Analytics) reads vector_db_key from the global config.
  4. Connection: The adapter injects the key into the provider's client constructor, establishing an authenticated connection.

The key remains in memory (or an optional config file) and is never written to the knowledge graph repository. When printed, the value is masked as "*****" to prevent accidental exposure in logs.

Verifying Your API Key Configuration

To confirm your API key is set correctly without exposing the full secret, retrieve the configuration object:

from cognee.infrastructure.databases.vector import get_vectordb_config

conf = get_vectordb_config()
print("Vector DB provider:", conf.vector_db_provider)
print("API key prefix:", conf.vector_db_key[:4] + "***")

This outputs the configured provider and a truncated version of the key, confirming authentication is ready without security risks.

Summary

  • Use cognee.config.set_vector_db_key() for immediate, in-memory API key updates.
  • Use cognee.config.set_vector_db_config() when loading multiple settings from external files.
  • Use save_vector_db_config() when you need to persist credentials across restarts.
  • The API key is stored in the global VectorDBConfig singleton and consumed by vector adapters when creating client connections.
  • All configuration methods validate input against the Pydantic model in cognee/infrastructure/databases/vector/models/VectorConfig.py.

Frequently Asked Questions

Where is the vector database API key stored in Cognee?

The API key is stored in the vector_db_key attribute of the global VectorDBConfig singleton, accessible via get_vectordb_config() from cognee.infrastructure.databases.vector. By default, this resides in memory only, though you can persist it to a configuration file using save_vector_db_config().

Can I set the vector database API key using environment variables?

While the raw analysis focuses on the programmatic API, Cognee's configuration system typically checks environment variables during initialization. However, for explicit runtime control, use cognee.config.set_vector_db_key() to override any default values before initializing the vector engine.

Which vector database providers require an API key in Cognee?

Cognee supports multiple vector backends including PGVector, ChromaDB, and Neptune Analytics. Cloud-hosted instances of these services (such as managed ChromaDB or Neptune Analytics) typically require API key authentication, while local instances may use URL-based authentication without keys.

How do I rotate or update the API key after Cognee has started?

Call cognee.config.set_vector_db_key() with the new key at any time. Since the configuration is a singleton, the update immediately affects new vector engine instances. For existing connections, you may need to reinitialize the vector engine by calling get_vector_engine() again to create a fresh authenticated client.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →