v124

OpenAPI 3.1.0MITraw.githubusercontent.com2026-08-01957351.2 MB
BYOK

Create a BYOK provider credential

Create a new bring-your-own-key (BYOK) provider credential. The raw key is encrypted at rest and never returned in API responses. Defaults to the authenticated entity's default workspace; use the workspace_id body field to scope to a different workspace. Treat the raw key as write-only; it is never returned after creation. Management key required.

post/byok

Request body

allowed_modelsstring[] nullable

Optional allowlist of model slugs this credential may be used for. null means no restriction.

allowed_user_idsstring[] nullable

Optional allowlist of user IDs that may use this credential. null means no restriction.

disabledboolean

Whether this credential should be created in a disabled state.

is_fallbackboolean

Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried.

keystring required

The raw provider API key or credential. This value is encrypted at rest and never returned in API responses.

namestring nullable

Optional human-readable name for the credential.

provider'ai21' | 'aion-labs' | 'akashml' | 'alibaba' | 'amazon-bedrock' | 'amazon-nova' | 'ambient' | 'anthropic' | 'arcee-ai' | 'atlas-cloud' | 'avian' | 'azure' | 'baidu' | 'baseten' | 'black-forest-labs' | 'byteplus' | 'cerebras' | 'chutes' | 'cirrascale' | 'clarifai' | 'cloudflare' | 'cohere' | 'coreweave' | 'crusoe' | 'darkbloom' | 'decart' | 'deepgram' | 'deepinfra' | 'deepseek' | 'dekallm' | 'digitalocean' | 'featherless' | 'fireworks' | 'fish-audio' | 'friendli' | 'gmicloud' | 'google-ai-studio' | 'google-vertex' | 'groq' | 'heygen' | 'inception' | 'inceptron' | 'inferact-vllm' | 'inference-net' | 'infermatic' | 'inflection' | 'io-net' | 'ionstream' | 'krea' | 'liquid' | 'mancer' | 'mara' | 'meta' | 'minimax' | 'mistral' | 'modal' | 'modelrun' | 'modular' | 'moonshotai' | 'morph' | 'ncompass' | 'nebius' | 'nex-agi' | 'nextbit' | 'novita' | 'nvidia' | 'open-inference' | 'openai' | 'parasail' | 'perceptron' | 'perplexity' | 'phala' | 'poolside' | 'quiver' | 'recraft' | 'reka' | 'relace' | 'runway' | 'sail-research' | 'sakana' | 'sakana-ai' | 'sambanova' | 'seed' | 'siliconflow' | 'sourceful' | 'stepfun' | 'streamlake' | 'switchpoint' | 'tencent' | 'tenstorrent' | 'thinkingmachines' | 'together' | 'upstage' | 'venice' | 'wafer' | 'wandb' | 'wandb-legacy' | 'xai' | 'xiaomi' | 'z-ai' required

The upstream provider this credential authenticates against, as a lowercase slug (e.g. openai, anthropic, amazon-bedrock).

workspace_idstring uuid

Optional workspace ID. Defaults to the authenticated entity's default workspace.

Example request

{
  "key": "sk-proj-abc123...",
  "name": "Production OpenAI Key",
  "provider": "openai"
}

Response

BYOK credential created successfully

Example response

{
  "data": {
    "allowed_api_key_hashes": null,
    "allowed_models": null,
    "allowed_user_ids": null,
    "created_at": "2025-08-24T10:30:00Z",
    "disabled": false,
    "id": "11111111-2222-3333-4444-555555555555",
    "is_fallback": false,
    "label": "sk-...AbCd",
    "name": "Production OpenAI Key",
    "provider": "openai",
    "sort_order": 0,
    "workspace_id": "550e8400-e29b-41d4-a716-446655440000"
  }
}