Why does Codestral offer both codestral.mistral.ai and the la Plateforme endpoint?
answer
- Two hosts, two credentials
- Not a model difference
- Code-only front door vs general platform
- 401 means wrong key for that host
- Pin base URL and key together
basics
~20 sThey are two front doors with different keys and different billing. codestral.mistral.ai is the dedicated code endpoint aimed at IDE-style completion and takes a Codestral API key; api.mistral.ai is the general la Plateforme endpoint using your normal workspace key and standard per-token billing. Keys are not interchangeable.
solid answer
~50 sCodestral is reachable two ways, and the distinction is about credentials and commercial terms rather than about the model. The dedicated endpoint at `codestral.mistral.ai` exposes the code routes — FIM completions and chat completions for Codestral models — and authenticates with a **Codestral API key**, issued separately and aimed at developer/IDE-plugin usage. The general endpoint on la Plateforme (`api.mistral.ai`) serves Codestral alongside every other model and route, authenticated by your ordinary workspace API key with standard per-token billing and workspace rate limits. A key minted for one will not authenticate against the other, which is the practical trap: an integration that works locally with a Codestral key fails with a 401 the moment someone points it at la Plateforme without swapping credentials. Build for one base URL, make it configurable, and keep the matching key beside it.
go deeper
Know there are two ways in — a dedicated code endpoint and the general Mistral platform — and that each needs its own API key. Do not assume one key works everywhere.
Explain what each host serves: code routes only on the dedicated endpoint, the full surface including embeddings, OCR and batch on la Plateforme, with the request shape identical on both.
Diagnose the 401-from-mismatched-pair failure and prescribe the fix: base URL and key configured and validated as one unit, with a startup smoke call so the mismatch surfaces at deploy rather than in a user's editor.
Own the choice as a cost-and-operations decision — a second credential and billing surface bought in exchange for isolating code-completion spend — and keep self-deployment of the weights on the table when source code cannot leave the network.
## Two doors, one model family When people first wire up Codestral they hit an oddity: the docs show two different hosts. This is not a versioning accident and it is not two different models. It is two access paths with different credentials, different intended audiences and different commercial terms. **`codestral.mistral.ai`** — the dedicated code endpoint. It carries the code-oriented routes: `/v1/fim/completions` for fill-in-the-middle and `/v1/chat/completions` for instruct-style code chat, for Codestral models. It authenticates with a **Codestral API key**, which is issued separately from your normal platform key and is oriented at developers wiring the model into an editor. **`api.mistral.ai`** — la Plateforme, the general API. Codestral is one model among many here, sitting next to `mistral-embed`, the OCR route, batch jobs and every chat model. It authenticates with your standard workspace API key, bills per token like everything else on the platform, and is governed by your workspace rate limits. ## The rule that bites people **Keys are not interchangeable.** A workspace key does not authenticate against the dedicated code endpoint, and a Codestral key does not unlock the rest of la Plateforme. The resulting failure is a plain `401`, which is easy to misdiagnose as a typo or an expired secret when it is actually the wrong pairing of host and credential. The defensive design is boring and effective: treat base URL and API key as a single configuration unit. One environment variable pair, validated together at startup, never two independently-set values that can drift apart between environments. A smoke call at boot that fails loudly beats a `401` discovered by a user mid-keystroke. ## Choosing between them For a production service that already talks to Mistral for other things — chat, embeddings, OCR — la Plateforme is the simpler answer. One key, one billing surface, one set of rate limits to reason about, one place to look at usage, and no second credential to rotate. The operational cost of a second key is real and recurring. The dedicated code endpoint earns its place when Codestral usage is separable from everything else: an editor plugin, a developer-tooling product, or a team that wants code-completion spend isolated from platform spend. Its commercial terms have been aimed specifically at that IDE-integration audience. A third path exists and belongs in the same conversation: Codestral's weights can be self-deployed, which moves the question from "which hosted endpoint" to "hosted or on our own hardware" — relevant when source code cannot leave your network at all. ## What does not differ The request shape. FIM is FIM on either host: `prompt` for the code before the cursor, `suffix` for the code after it, and the model returns the middle. Response envelopes match too. So porting an integration from one host to the other is genuinely a base-URL-plus-key change — provided the routes you use actually exist on the host you are moving to. That caveat matters in the other direction: the dedicated code endpoint is code-only, so an application that also calls embeddings, OCR or batch jobs must talk to la Plateforme for those regardless. ## Version caution Hosted product packaging is the fastest-rotting part of any vendor's surface, faster even than model names. The endpoint split, the key types and the commercial terms described here reflect the situation as of mid-2026. The durable interview answer is the *shape* of the arrangement — a dedicated code front door with its own credential versus the general platform key — plus the operational discipline of pinning base URL and key together. Reciting a specific price or free-tier allowance is exactly the kind of claim that will be stale by the time you are asked it.
- Your service already calls Mistral for embeddings and OCR and now wants Codestral completion. Which endpoint?La Plateforme. You are already authenticated there, embeddings and OCR only exist there, and adding the code route costs you nothing extra operationally — one key, one billing surface, one rate-limit budget, one credential to rotate. Taking on a second endpoint and a second key to reach the same model family is complexity you would be paying for permanently with no capability gained.
- An engineer reports 401s after deploying a Codestral integration that worked on their laptop. What is your first hypothesis?A mismatched base URL and key. A Codestral API key does not authenticate against la Plateforme and a workspace key does not authenticate against the dedicated code endpoint, so an environment that inherited one value but not the other fails exactly this way. Check the pair together, and make the two values a single configuration unit validated at startup so the mismatch cannot ship again.
- Does switching between the two hosts change the FIM request you send?No — the fill-in-the-middle contract is the same on both: `prompt` for the code before the cursor, `suffix` for the code after, and the generated middle comes back in a chat-shaped response. Only the base URL and the credential change. The asymmetry is in coverage, not in shape: the dedicated code endpoint serves code routes only, so embeddings, OCR and batch jobs still require la Plateforme.
saying these in an interview costs you the question
- Thinking the two hosts serve different Codestral models
- Assuming one API key works against both endpoints
- Expecting embeddings or OCR on the code-only endpoint
- Hardcoding the base URL with a separately-configured key
- Quoting a specific free-tier allowance as permanent