You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .speakeasy/in.openapi.yaml
+284-3Lines changed: 284 additions & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -7315,6 +7315,16 @@ components:
7315
7315
name: 'My New Guardrail'
7316
7316
reset_interval: 'monthly'
7317
7317
properties:
7318
+
allowed_data_regions:
7319
+
description: 'Data regions through which requests governed by this guardrail must arrive. `global` is https://openrouter.ai, `europe` is https://eu.openrouter.ai, and `us` is https://us.openrouter.ai. Requests arriving through any other region are rejected. `null` leaves the ingress region unrestricted. When several guardrails apply (workspace default, member, API key), the effective regions are the intersection of every non-null value. An empty array is rejected.'
7320
+
example:
7321
+
- 'europe'
7322
+
items:
7323
+
$ref: '#/components/schemas/GuardrailDataRegion'
7324
+
minItems: 1
7325
+
type:
7326
+
- 'array'
7327
+
- 'null'
7318
7328
allowed_models:
7319
7329
description: 'Array of model identifiers (slug or canonical_slug accepted)'
description: 'Data regions through which requests governed by this guardrail must arrive. `global` is https://openrouter.ai, `europe` is https://eu.openrouter.ai, and `us` is https://us.openrouter.ai. Requests arriving through any other region are rejected. `null` leaves the ingress region unrestricted. When several guardrails apply (workspace default, member, API key), the effective regions are the intersection of every non-null value.'
10201
+
example:
10202
+
- 'europe'
10203
+
items:
10204
+
$ref: '#/components/schemas/GuardrailDataRegion'
10205
+
type:
10206
+
- 'array'
10207
+
- 'null'
10188
10208
allowed_models:
10189
10209
description: 'Array of model canonical_slugs (immutable identifiers)'
10190
10210
example:
@@ -10353,6 +10373,14 @@ components:
10353
10373
- 'created_at'
10354
10374
- 'workspace_id'
10355
10375
type: 'object'
10376
+
GuardrailDataRegion:
10377
+
description: 'An OpenRouter data region: `global` (https://openrouter.ai), `europe` (https://eu.openrouter.ai), or `us` (https://us.openrouter.ai)'
10378
+
enum:
10379
+
- 'global'
10380
+
- 'europe'
10381
+
- 'us'
10382
+
example: 'europe'
10383
+
type: 'string'
10356
10384
GuardrailInterval:
10357
10385
description: 'Interval at which the limit resets (daily, weekly, monthly)'
10358
10386
enum:
@@ -14940,6 +14968,82 @@ components:
14940
14968
- 'code'
14941
14969
- 'message'
14942
14970
type: 'object'
14971
+
OAuthErrorResponse:
14972
+
description: 'RFC 6749 §5.2 error response.'
14973
+
example:
14974
+
error: 'invalid_grant'
14975
+
error_description: 'The subject token was not accepted.'
14976
+
properties:
14977
+
error:
14978
+
enum:
14979
+
- 'invalid_request'
14980
+
- 'invalid_grant'
14981
+
- 'unsupported_grant_type'
14982
+
- 'invalid_scope'
14983
+
- 'server_error'
14984
+
- 'temporarily_unavailable'
14985
+
type: 'string'
14986
+
error_description:
14987
+
type: 'string'
14988
+
required:
14989
+
- 'error'
14990
+
- 'error_description'
14991
+
type: 'object'
14992
+
OAuthJwks:
14993
+
description: 'RFC 7517 JWK Set of the keys OpenRouter signs access tokens with.'
description: 'Data regions through which requests governed by this guardrail must arrive. `global` is https://openrouter.ai, `europe` is https://eu.openrouter.ai, and `us` is https://us.openrouter.ai. Requests arriving through any other region are rejected. `null` leaves the ingress region unrestricted. When several guardrails apply (workspace default, member, API key), the effective regions are the intersection of every non-null value. An empty array is rejected.'
25925
+
example:
25926
+
- 'europe'
25927
+
items:
25928
+
$ref: '#/components/schemas/GuardrailDataRegion'
25929
+
minItems: 1
25930
+
type:
25931
+
- 'array'
25932
+
- 'null'
25733
25933
allowed_models:
25734
25934
description: 'Array of model identifiers (slug or canonical_slug accepted)'
25735
25935
example:
@@ -34090,7 +34290,7 @@ paths:
34090
34290
- 'API Keys'
34091
34291
x-speakeasy-name-override: 'list'
34092
34292
post:
34093
-
description: 'Create a new API key for the authenticated user. The plaintext `key` is returned only in this response. Treat it as a write-only, sensitive value; it cannot be retrieved later. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys), or with a Connect client secret.'
34293
+
description: 'Create a new API key for the authenticated user. The plaintext `key` is returned only in this response. Treat it as a write-only, sensitive value; it cannot be retrieved later. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys). The optional `external` object associates the key with a partner-defined user and lookup key.'
34094
34294
operationId: 'createKeys'
34095
34295
requestBody:
34096
34296
content:
@@ -34123,6 +34323,23 @@ paths:
34123
34323
type:
34124
34324
- 'string'
34125
34325
- 'null'
34326
+
external:
34327
+
description: 'Optional partner-defined identity associated with the created API key.'
34328
+
properties:
34329
+
api_key:
34330
+
description: 'Optional partner-supplied API key with a minimum length of 32 characters and sufficient entropy. Stored as a SHA-256 hash and never returned.'
34331
+
maxLength: 512
34332
+
minLength: 32
34333
+
type: 'string'
34334
+
user:
34335
+
description: 'Partner''s end-user identifier for attribution.'
34336
+
example: 'partner-user-123'
34337
+
maxLength: 512
34338
+
minLength: 1
34339
+
type: 'string'
34340
+
required:
34341
+
- 'user'
34342
+
type: 'object'
34126
34343
include_byok_in_limit:
34127
34344
description: 'Whether to include BYOK usage in the limit'
34128
34345
example: true
@@ -34442,7 +34659,7 @@ paths:
34442
34659
x-speakeasy-name-override: 'create'
34443
34660
/keys/{hash}:
34444
34661
delete:
34445
-
description: 'Delete an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys), or with a Connect client secret. A client secret reaches only the keys that same client created; any other key responds as if it does not exist.'
34662
+
description: 'Delete an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys).'
34446
34663
operationId: 'deleteKeys'
34447
34664
parameters:
34448
34665
- description: 'The hash identifier of the API key to delete'
@@ -34792,7 +35009,7 @@ paths:
34792
35009
- 'API Keys'
34793
35010
x-speakeasy-name-override: 'get'
34794
35011
patch:
34795
-
description: 'Update an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys), or with a Connect client secret. A client secret reaches only the keys that same client created; any other key responds as if it does not exist.'
35012
+
description: 'Update an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys).'
34796
35013
operationId: 'updateKeys'
34797
35014
parameters:
34798
35015
- description: 'The hash identifier of the API key to update'
@@ -36159,6 +36376,70 @@ paths:
36159
36376
outputs:
36160
36377
results: '$.data'
36161
36378
type: 'offsetLimit'
36379
+
/oauth/jwks:
36380
+
get:
36381
+
description: 'RFC 7517 JWK Set containing the public keys OpenRouter signs access tokens with.'
description: 'RFC 8693 token exchange. Presents a JWT from an issuer your organization trusts (Settings → Workload identity) and receives a short-lived OpenRouter access token that acts as the API key the matching federation policy targets.'
description: 'Malformed request, unsupported grant, or the subject token was not accepted'
36422
+
'429':
36423
+
content:
36424
+
application/json:
36425
+
schema:
36426
+
$ref: '#/components/schemas/OAuthErrorResponse'
36427
+
description: 'Rate limited'
36428
+
'500':
36429
+
content:
36430
+
application/json:
36431
+
schema:
36432
+
$ref: '#/components/schemas/OAuthErrorResponse'
36433
+
description: 'The token could not be issued'
36434
+
'503':
36435
+
content:
36436
+
application/json:
36437
+
schema:
36438
+
$ref: '#/components/schemas/OAuthErrorResponse'
36439
+
description: 'The issuer’s discovery document or JWKS could not be fetched'
36440
+
summary: 'Exchange a workload identity token'
36441
+
tags:
36442
+
- 'OAuth'
36162
36443
/observability/destinations:
36163
36444
get:
36164
36445
description: 'List the observability destinations configured for the authenticated entity''s default workspace. Use the `workspace_id` query parameter to scope the result to a different workspace. Only destinations with stable release status are surfaced — destinations of other types are excluded. [Management key](/docs/guides/overview/auth/management-api-keys) required.'
0 commit comments