Hosted model APIs

How to use
Replicate.

Testing public generative models, integrating versioned predictions, running asynchronous media jobs, and deploying custom model versions.

What it ishosted API platform for running and deploying machine-learning models Workflows2 UpdatedJuly 2026

Replicate is a hosted API platform for running and deploying machine-learning models. Testing public generative models, integrating versioned predictions, running asynchronous media jobs, and deploying custom model versions. This guide covers the whole path in one place: official access, a first session that produces something reviewable, the checks that make output trustworthy, and the permissions worth limiting before you connect real work.

Troiana principle

AI should make the work easier to inspect. If the workflow removes the source, the owner, or the review step, redesign the workflow.

01

Access & setup

Find, install, and sign in to Replicate

Get into the official Replicate experience with the right account and a setup you understand.

  1. 01

    Start at https://replicate.com/ and confirm the domain before entering account or payment information.

  2. 02

    Availability: Replicate is accessed through its website, HTTP API, and official client libraries rather than a required desktop application.

  3. 03

    A Replicate account and API token, network access, and a secure server-side or development environment for API integration.

  4. 04

    Sign in with the account you intend to keep using, then review plan, data, notification, and permission settings.

  5. 05

    Run one low-risk test task before connecting sensitive files, repositories, or workspace data.

  • Use official download pages.
  • Review permissions during setup.
  • Keep installers and applications updated.
02

First session

Your first useful Replicate session

Learn the interaction loop using a small task with a clear outcome.

  1. 01

    Choose a model after reviewing its owner, README, license, schema, examples, and exact version.

  2. 02

    Run representative low-risk inputs in the web interface and record settings, quality, time, and cost.

  3. 03

    Create a server-side API token and reproduce the selected prediction with an explicit version when supported.

  4. 04

    Persist the prediction ID and copy any required output files to durable storage before their API retention expires.

  • State the outcome before the background.
  • Provide the real source material.
  • Review the result before expanding the task.
03

Quality control

Check the quality of Replicate output

Establish that a change is safe to run in production and reversible if it is not.

  1. 01

    Restate the intended end state and the blast radius before applying anything.

  2. 02

    Review the generated configuration line by line against the provider's current documentation.

  3. 03

    Apply to a non-production environment first and confirm the observed result matches the intended one.

  4. 04

    Confirm the rollback path works by actually exercising it, not by assuming it exists.

  5. 05

    Check cost, scaling limits, and network exposure before the change reaches production traffic.

  • Test the rollback, do not assume it.
  • Check what a configuration exposes to the public internet.
  • Watch cost and rate limits as closely as correctness.
04

Privacy & permissions

Use Replicate safely

Keep credentials, network exposure, and cost under deliberate control.

  1. 01

    Use scoped, short-lived credentials, and never paste production secrets into a prompt or config file.

  2. 02

    Confirm what each change exposes publicly before applying it, especially storage, databases, and admin endpoints.

  3. 03

    Separate environments so a mistake in development cannot reach production data.

  4. 04

    Set billing alerts and hard quotas before enabling autoscaling or usage-based services.

  5. 05

    Review audit logs and revoke access for integrations that are no longer in use.

  • Community models vary in quality, licensing, and safety. Protect API tokens, pin versions, validate inputs and outputs, make webhook processing idempotent, and do not assume generated files remain available permanently.
  • Follow your organisation's approved-use policy.
  • Never treat fluent output as authorization to act.
05

Core workflows

Step-by-step ways to use Replicate for the work it does best.

Each workflow is a separate guide with its own steps and review checkpoints.

06

Official references

Check the current product documentation.

Features, plan limits, availability, and data controls change. These official pages are the starting points used for this guide.

Explore the Troiana AI Hub →