Skip to content

Commit 3249d2e

Browse files
author
OpenRouter SDK Bot
committed
chore: update OpenAPI spec [sdk-bot]
1 parent df79ecb commit 3249d2e

1 file changed

Lines changed: 284 additions & 3 deletions

File tree

‎.speakeasy/in.openapi.yaml‎

Lines changed: 284 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7315,6 +7315,16 @@ components:
73157315
name: 'My New Guardrail'
73167316
reset_interval: 'monthly'
73177317
properties:
7318+
allowed_data_regions:
7319+
description: 'Data regions through which requests governed by this guardrail must arrive. `global` is https://openrouter.ai, `europe` is https://eu.openrouter.ai, and `us` is https://us.openrouter.ai. Requests arriving through any other region are rejected. `null` leaves the ingress region unrestricted. When several guardrails apply (workspace default, member, API key), the effective regions are the intersection of every non-null value. An empty array is rejected.'
7320+
example:
7321+
- 'europe'
7322+
items:
7323+
$ref: '#/components/schemas/GuardrailDataRegion'
7324+
minItems: 1
7325+
type:
7326+
- 'array'
7327+
- 'null'
73187328
allowed_models:
73197329
description: 'Array of model identifiers (slug or canonical_slug accepted)'
73207330
example:
@@ -10154,6 +10164,7 @@ components:
1015410164
type: 'object'
1015510165
Guardrail:
1015610166
example:
10167+
allowed_data_regions: null
1015710168
allowed_models: null
1015810169
allowed_providers:
1015910170
- 'openai'
@@ -10185,6 +10196,15 @@ components:
1018510196
updated_at: '2025-08-24T15:45:00Z'
1018610197
workspace_id: '0df9e665-d932-5740-b2c7-b52af166bc11'
1018710198
properties:
10199+
allowed_data_regions:
10200+
description: 'Data regions through which requests governed by this guardrail must arrive. `global` is https://openrouter.ai, `europe` is https://eu.openrouter.ai, and `us` is https://us.openrouter.ai. Requests arriving through any other region are rejected. `null` leaves the ingress region unrestricted. When several guardrails apply (workspace default, member, API key), the effective regions are the intersection of every non-null value.'
10201+
example:
10202+
- 'europe'
10203+
items:
10204+
$ref: '#/components/schemas/GuardrailDataRegion'
10205+
type:
10206+
- 'array'
10207+
- 'null'
1018810208
allowed_models:
1018910209
description: 'Array of model canonical_slugs (immutable identifiers)'
1019010210
example:
@@ -10353,6 +10373,14 @@ components:
1035310373
- 'created_at'
1035410374
- 'workspace_id'
1035510375
type: 'object'
10376+
GuardrailDataRegion:
10377+
description: 'An OpenRouter data region: `global` (https://openrouter.ai), `europe` (https://eu.openrouter.ai), or `us` (https://us.openrouter.ai)'
10378+
enum:
10379+
- 'global'
10380+
- 'europe'
10381+
- 'us'
10382+
example: 'europe'
10383+
type: 'string'
1035610384
GuardrailInterval:
1035710385
description: 'Interval at which the limit resets (daily, weekly, monthly)'
1035810386
enum:
@@ -14940,6 +14968,82 @@ components:
1494014968
- 'code'
1494114969
- 'message'
1494214970
type: 'object'
14971+
OAuthErrorResponse:
14972+
description: 'RFC 6749 §5.2 error response.'
14973+
example:
14974+
error: 'invalid_grant'
14975+
error_description: 'The subject token was not accepted.'
14976+
properties:
14977+
error:
14978+
enum:
14979+
- 'invalid_request'
14980+
- 'invalid_grant'
14981+
- 'unsupported_grant_type'
14982+
- 'invalid_scope'
14983+
- 'server_error'
14984+
- 'temporarily_unavailable'
14985+
type: 'string'
14986+
error_description:
14987+
type: 'string'
14988+
required:
14989+
- 'error'
14990+
- 'error_description'
14991+
type: 'object'
14992+
OAuthJwks:
14993+
description: 'RFC 7517 JWK Set of the keys OpenRouter signs access tokens with.'
14994+
example:
14995+
keys:
14996+
- alg: 'ES256'
14997+
crv: 'P-256'
14998+
kid: 'or-2026-09'
14999+
kty: 'EC'
15000+
use: 'sig'
15001+
x: 'f83OJ3D2xF1Bg8vub9tLe1gHMzV76e8Tus9uPHvRVEU'
15002+
'y': 'x_FEzRu9m36HLN_tue659LNpXW6pCyStikYjKIWI5a0'
15003+
properties:
15004+
keys:
15005+
items:
15006+
additionalProperties: false
15007+
properties:
15008+
alg:
15009+
enum:
15010+
- 'ES256'
15011+
type: 'string'
15012+
crv:
15013+
enum:
15014+
- 'P-256'
15015+
type: 'string'
15016+
kid:
15017+
minLength: 1
15018+
type: 'string'
15019+
kty:
15020+
enum:
15021+
- 'EC'
15022+
type: 'string'
15023+
use:
15024+
enum:
15025+
- 'sig'
15026+
type: 'string'
15027+
x:
15028+
pattern: '^[A-Za-z0-9_-]+$'
15029+
type: 'string'
15030+
'y':
15031+
pattern: '^[A-Za-z0-9_-]+$'
15032+
type: 'string'
15033+
required:
15034+
- 'kty'
15035+
- 'crv'
15036+
- 'kid'
15037+
- 'x'
15038+
- 'y'
15039+
- 'alg'
15040+
- 'use'
15041+
type: 'object'
15042+
minItems: 1
15043+
type: 'array'
15044+
required:
15045+
- 'keys'
15046+
type: 'object'
1494315047
ObservabilityArizeDestination:
1494415048
example:
1494515049
api_key_hashes: null
@@ -24917,6 +25021,92 @@ components:
2491725021
example:
2491825022
format:
2491925023
type: 'text'
25024+
TokenExchangeRequest:
25025+
description: 'RFC 8693 token exchange request body (application/x-www-form-urlencoded).'
25026+
example:
25027+
federation_policy_id: '4b2f7d1e-8c3a-4e5f-9a6b-1c2d3e4f5a6b'
25028+
grant_type: 'urn:ietf:params:oauth:grant-type:token-exchange'
25029+
subject_token: '<jwt from your identity provider>'
25030+
subject_token_type: 'urn:ietf:params:oauth:token-type:jwt'
25031+
properties:
25032+
federation_policy_id:
25033+
description: 'The federation policy to evaluate, from Settings → Workload identity. Binds the exchange to one organization.'
25034+
example: '4b2f7d1e-8c3a-4e5f-9a6b-1c2d3e4f5a6b'
25035+
format: 'uuid'
25036+
type: 'string'
25037+
grant_type:
25038+
description: 'Must be `urn:ietf:params:oauth:grant-type:token-exchange`.'
25039+
enum:
25040+
- 'urn:ietf:params:oauth:grant-type:token-exchange'
25041+
example: 'urn:ietf:params:oauth:grant-type:token-exchange'
25042+
type: 'string'
25043+
requested_token_type:
25044+
description: 'Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`.'
25045+
enum:
25046+
- 'urn:ietf:params:oauth:token-type:access_token'
25047+
example: 'urn:ietf:params:oauth:token-type:access_token'
25048+
type: 'string'
25049+
scope:
25050+
description: 'Optional; only `inference` is available.'
25051+
enum:
25052+
- 'inference'
25053+
example: 'inference'
25054+
type: 'string'
25055+
subject_token:
25056+
description: 'The JWT issued by your identity provider.'
25057+
example: '<jwt from your identity provider>'
25058+
maxLength: 16384
25059+
minLength: 1
25060+
type: 'string'
25061+
subject_token_type:
25062+
description: 'Must be `urn:ietf:params:oauth:token-type:jwt`.'
25063+
enum:
25064+
- 'urn:ietf:params:oauth:token-type:jwt'
25065+
example: 'urn:ietf:params:oauth:token-type:jwt'
25066+
type: 'string'
25067+
required:
25068+
- 'grant_type'
25069+
- 'subject_token'
25070+
- 'federation_policy_id'
25071+
- 'subject_token_type'
25072+
type: 'object'
25073+
TokenExchangeResponse:
25074+
description: 'RFC 8693 token exchange response.'
25075+
example:
25076+
access_token: '<short-lived openrouter access token jwt>'
25077+
expires_in: 900
25078+
issued_token_type: 'urn:ietf:params:oauth:token-type:access_token'
25079+
scope: 'inference'
25080+
token_type: 'Bearer'
25081+
properties:
25082+
access_token:
25083+
description: 'A short-lived JWT to send as `Authorization: Bearer` to the inference API.'
25084+
example: '<short-lived openrouter access token jwt>'
25085+
type: 'string'
25086+
expires_in:
25087+
description: 'Seconds until the access token expires: at most 15 minutes, and never later than the subject token expires.'
25088+
example: 900
25089+
type: 'integer'
25090+
issued_token_type:
25091+
enum:
25092+
- 'urn:ietf:params:oauth:token-type:access_token'
25093+
example: 'urn:ietf:params:oauth:token-type:access_token'
25094+
type: 'string'
25095+
scope:
25096+
example: 'inference'
25097+
type: 'string'
25098+
token_type:
25099+
enum:
25100+
- 'Bearer'
25101+
example: 'Bearer'
25102+
type: 'string'
25103+
required:
25104+
- 'access_token'
25105+
- 'issued_token_type'
25106+
- 'token_type'
25107+
- 'expires_in'
25108+
- 'scope'
25109+
type: 'object'
2492025110
ToolCallStatus:
2492125111
enum:
2492225112
- 'in_progress'
@@ -25730,6 +25920,16 @@ components:
2573025920
name: 'Updated Guardrail Name'
2573125921
reset_interval: 'weekly'
2573225922
properties:
25923+
allowed_data_regions:
25924+
description: 'Data regions through which requests governed by this guardrail must arrive. `global` is https://openrouter.ai, `europe` is https://eu.openrouter.ai, and `us` is https://us.openrouter.ai. Requests arriving through any other region are rejected. `null` leaves the ingress region unrestricted. When several guardrails apply (workspace default, member, API key), the effective regions are the intersection of every non-null value. An empty array is rejected.'
25925+
example:
25926+
- 'europe'
25927+
items:
25928+
$ref: '#/components/schemas/GuardrailDataRegion'
25929+
minItems: 1
25930+
type:
25931+
- 'array'
25932+
- 'null'
2573325933
allowed_models:
2573425934
description: 'Array of model identifiers (slug or canonical_slug accepted)'
2573525935
example:
@@ -34090,7 +34290,7 @@ paths:
3409034290
- 'API Keys'
3409134291
x-speakeasy-name-override: 'list'
3409234292
post:
34093-
description: 'Create a new API key for the authenticated user. The plaintext `key` is returned only in this response. Treat it as a write-only, sensitive value; it cannot be retrieved later. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys), or with a Connect client secret.'
34293+
description: 'Create a new API key for the authenticated user. The plaintext `key` is returned only in this response. Treat it as a write-only, sensitive value; it cannot be retrieved later. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys). The optional `external` object associates the key with a partner-defined user and lookup key.'
3409434294
operationId: 'createKeys'
3409534295
requestBody:
3409634296
content:
@@ -34123,6 +34323,23 @@ paths:
3412334323
type:
3412434324
- 'string'
3412534325
- 'null'
34326+
external:
34327+
description: 'Optional partner-defined identity associated with the created API key.'
34328+
properties:
34329+
api_key:
34330+
description: 'Optional partner-supplied API key with a minimum length of 32 characters and sufficient entropy. Stored as a SHA-256 hash and never returned.'
34331+
maxLength: 512
34332+
minLength: 32
34333+
type: 'string'
34334+
user:
34335+
description: 'Partner''s end-user identifier for attribution.'
34336+
example: 'partner-user-123'
34337+
maxLength: 512
34338+
minLength: 1
34339+
type: 'string'
34340+
required:
34341+
- 'user'
34342+
type: 'object'
3412634343
include_byok_in_limit:
3412734344
description: 'Whether to include BYOK usage in the limit'
3412834345
example: true
@@ -34442,7 +34659,7 @@ paths:
3444234659
x-speakeasy-name-override: 'create'
3444334660
/keys/{hash}:
3444434661
delete:
34445-
description: 'Delete an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys), or with a Connect client secret. A client secret reaches only the keys that same client created; any other key responds as if it does not exist.'
34662+
description: 'Delete an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys).'
3444634663
operationId: 'deleteKeys'
3444734664
parameters:
3444834665
- description: 'The hash identifier of the API key to delete'
@@ -34792,7 +35009,7 @@ paths:
3479235009
- 'API Keys'
3479335010
x-speakeasy-name-override: 'get'
3479435011
patch:
34795-
description: 'Update an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys), or with a Connect client secret. A client secret reaches only the keys that same client created; any other key responds as if it does not exist.'
35012+
description: 'Update an existing API key. Authenticate with a [management key](/docs/guides/overview/auth/management-api-keys).'
3479635013
operationId: 'updateKeys'
3479735014
parameters:
3479835015
- description: 'The hash identifier of the API key to update'
@@ -36159,6 +36376,70 @@ paths:
3615936376
outputs:
3616036377
results: '$.data'
3616136378
type: 'offsetLimit'
36379+
/oauth/jwks:
36380+
get:
36381+
description: 'RFC 7517 JWK Set containing the public keys OpenRouter signs access tokens with.'
36382+
operationId: 'listOauthJwks'
36383+
responses:
36384+
'200':
36385+
content:
36386+
application/json:
36387+
schema:
36388+
$ref: '#/components/schemas/OAuthJwks'
36389+
description: 'JWK Set'
36390+
'500':
36391+
content:
36392+
application/json:
36393+
schema:
36394+
$ref: '#/components/schemas/InternalServerResponse'
36395+
description: 'Signing keys are not configured'
36396+
summary: 'OpenRouter access token signing keys'
36397+
tags:
36398+
- 'OAuth'
36399+
/oauth/token:
36400+
post:
36401+
description: 'RFC 8693 token exchange. Presents a JWT from an issuer your organization trusts (Settings → Workload identity) and receives a short-lived OpenRouter access token that acts as the API key the matching federation policy targets.'
36402+
operationId: 'createOauthToken'
36403+
requestBody:
36404+
content:
36405+
application/x-www-form-urlencoded:
36406+
schema:
36407+
$ref: '#/components/schemas/TokenExchangeRequest'
36408+
required: true
36409+
responses:
36410+
'200':
36411+
content:
36412+
application/json:
36413+
schema:
36414+
$ref: '#/components/schemas/TokenExchangeResponse'
36415+
description: 'Access token issued'
36416+
'400':
36417+
content:
36418+
application/json:
36419+
schema:
36420+
$ref: '#/components/schemas/OAuthErrorResponse'
36421+
description: 'Malformed request, unsupported grant, or the subject token was not accepted'
36422+
'429':
36423+
content:
36424+
application/json:
36425+
schema:
36426+
$ref: '#/components/schemas/OAuthErrorResponse'
36427+
description: 'Rate limited'
36428+
'500':
36429+
content:
36430+
application/json:
36431+
schema:
36432+
$ref: '#/components/schemas/OAuthErrorResponse'
36433+
description: 'The token could not be issued'
36434+
'503':
36435+
content:
36436+
application/json:
36437+
schema:
36438+
$ref: '#/components/schemas/OAuthErrorResponse'
36439+
description: 'The issuer’s discovery document or JWKS could not be fetched'
36440+
summary: 'Exchange a workload identity token'
36441+
tags:
36442+
- 'OAuth'
3616236443
/observability/destinations:
3616336444
get:
3616436445
description: 'List the observability destinations configured for the authenticated entity''s default workspace. Use the `workspace_id` query parameter to scope the result to a different workspace. Only destinations with stable release status are surfaced — destinations of other types are excluded. [Management key](/docs/guides/overview/auth/management-api-keys) required.'

0 commit comments

Comments
 (0)