key management

Generate Service Account Key Fn

Generate a Service Account API key based on the provided data. This key does not belong to any user. It belongs to the team.

Why use a service account key?

  • Prevent key from being deleted when user is deleted.
  • Apply team limits, not team member limits to key.

Docs: https://docs.litellm.ai/docs/proxy/virtual_keys

Parameters:

  • duration: Optional[str] - Specify the length of time the token is valid for. You can set duration as seconds ("30s"), minutes ("30m"), hours ("30h"), days ("30d").
  • key_alias: Optional[str] - User defined key alias
  • key: Optional[str] - User defined key value. If not set, a 16-digit unique sk-key is created for you.
  • team_id: Optional[str] - The team id of the key
  • user_id: Optional[str] - [NON-FUNCTIONAL] THIS WILL BE IGNORED. The user id of the key
  • budget_id: Optional[str] - The budget id associated with the key. Created by calling /budget/new.
  • models: Optional[list] - Model_name's a user is allowed to call. (if empty, key is allowed to call all models)
  • aliases: Optional[dict] - Any alias mappings, on top of anything in the config.yaml model list. - https://docs.litellm.ai/docs/proxy/virtual_keys#managing-auth---upgradedowngrade-models
  • config: Optional[dict] - any key-specific configs, overrides config in config.yaml
  • spend: Optional[int] - Amount spent by key. Default is 0. Will be updated by proxy whenever key is used. https://docs.litellm.ai/docs/proxy/virtual_keys#managing-auth---tracking-spend
  • send_invite_email: Optional[bool] - Whether to send an invite email to the user_id, with the generate key
  • max_budget: Optional[float] - Specify max budget for a given key.
  • budget_duration: Optional[str] - Budget is reset at the end of specified duration. If not set, budget is never reset. You can set duration as seconds ("30s"), minutes ("30m"), hours ("30h"), days ("30d").
  • max_parallel_requests: Optional[int] - Rate limit a user based on the number of parallel requests. Raises 429 error, if user's parallel requests > x.
  • metadata: Optional[dict] - Metadata for key, store information for key. Example metadata = {"team": "core-infra", "app": "app2", "email": "ishaan@berri.ai" }
  • guardrails: Optional[List[str]] - List of active guardrails for the key
  • permissions: Optional[dict] - key-specific permissions. Currently just used for turning off pii masking (if connected). Example - {"pii": false}
  • model_max_budget: Optional[Dict[str, BudgetConfig]] - Model-specific budgets {"gpt-4": {"budget_limit": 0.0005, "time_period": "30d"}}}. IF null or {} then no model specific budget.
  • model_rpm_limit: Optional[dict] - key-specific model rpm limit. Example - {"text-davinci-002": 1000, "gpt-3.5-turbo": 1000}. IF null or {} then no model specific rpm limit.
  • model_tpm_limit: Optional[dict] - key-specific model tpm limit. Example - {"text-davinci-002": 1000, "gpt-3.5-turbo": 1000}. IF null or {} then no model specific tpm limit.
  • tpm_limit_type: Optional[str] - TPM rate limit type - "best_effort_throughput", "guaranteed_throughput", or "dynamic"
  • rpm_limit_type: Optional[str] - RPM rate limit type - "best_effort_throughput", "guaranteed_throughput", or "dynamic"
  • allowed_cache_controls: Optional[list] - List of allowed cache control values. Example - ["no-cache", "no-store"]. See all values - https://docs.litellm.ai/docs/proxy/caching#turn-on--off-caching-per-request
  • blocked: Optional[bool] - Whether the key is blocked.
  • rpm_limit: Optional[int] - Specify rpm limit for a given key (Requests per minute)
  • tpm_limit: Optional[int] - Specify tpm limit for a given key (Tokens per minute)
  • soft_budget: Optional[float] - Specify soft budget for a given key. Will trigger a slack alert when this soft budget is reached.
  • tags: Optional[List[str]] - Tags for tracking spend and/or doing tag-based routing.
  • enforced_params: Optional[List[str]] - List of enforced params for the key (Enterprise only). Docs
  • allowed_routes: Optional[list] - List of allowed routes for the key. Store the actual route or store a wildcard pattern for a set of routes. Example - ["/chat/completions", "/embeddings", "/keys/*"]
  • object_permission: Optional[LiteLLM_ObjectPermissionBase] - key-specific object permission. Example - {"vector_stores": ["vector_store_1", "vector_store_2"], "agents": ["agent_1", "agent_2"], "agent_access_groups": ["dev_group"]}. IF null or {} then no object permission. Examples:
  • allowed_vector_store_indexes: Optional[List[dict]] - List of allowed vector store indexes for the key. Example - [{"index_name": "my-index", "index_permissions": ["write", "read"]}]. If specified, the key will only be able to use these specific vector store indexes. Create index, using /v1/indexes endpoint.
  1. Allow users to turn on/off pii masking
curl --location 'http://0.0.0.0:4000/key/generate'         --header 'Authorization: Bearer sk-1234'         --header 'Content-Type: application/json'         --data '{
        "permissions": {"allow_pii_controls": true}
}'

Returns:

  • key: (str) The generated api key
  • expires: (datetime) Datetime object for when key expires.
  • user_id: (str) Unique user id - used for tracking spend across multiple keys for same user id.
post/key/service-account/generate

Headers

litellm-changed-bystring nullable

The litellm-changed-by header enables tracking of actions performed by authorized users on behalf of other users, providing an audit trail for accountability

The litellm-changed-by header enables tracking of actions performed by authorized users on behalf of other users, providing an audit trail for accountability

Request body

key_aliasstring nullable
durationstring nullable
spendnumber nullable
max_budgetnumber nullable
user_idstring nullable
team_idstring nullable
agent_idstring nullable
max_parallel_requestsinteger nullable
metadataobject nullable
tpm_limitinteger nullable
rpm_limitinteger nullable
budget_durationstring nullable
configobject nullable
permissionsobject nullable
model_max_budgetobject nullable
model_rpm_limitobject nullable
model_tpm_limitobject nullable
guardrailsstring[] nullable
policiesstring[] nullable
promptsstring[] nullable
blockedboolean nullable
aliasesobject nullable
keystring nullable
budget_idstring nullable
tagsstring[] nullable
enforced_paramsstring[] nullable
rpm_limit_type'guaranteed_throughput' | 'best_effort_throughput' | 'dynamic' nullable
tpm_limit_type'guaranteed_throughput' | 'best_effort_throughput' | 'dynamic' nullable
access_group_idsstring[] nullable
soft_budgetnumber nullable
send_invite_emailboolean nullable
key_type'llm_api' | 'management' | 'read_only' | 'default'

Enum for key types that determine what routes a key can access

auto_rotateboolean nullable

Whether this key should be automatically rotated

rotation_intervalstring nullable

How often to rotate this key (e.g., '30d', '90d'). Required if auto_rotate=True

organization_idstring nullable
project_idstring nullable

Response

Successful Response

{"stackTrail":"paths:/key/service-account/generate:post:responses:200:content:application/json:schema","oasType":"schema","type":"unknown"}