@@ -15088,6 +15088,83 @@ components:
1508815088 - 'code'
1508915089 - 'message'
1509015090 type: 'object'
15091+ OAuthErrorResponse:
15092+ description: 'RFC 6749 §5.2 error response.'
15093+ example:
15094+ error: 'invalid_grant'
15095+ error_description: 'The subject token was not accepted.'
15096+ properties:
15097+ error:
15098+ enum:
15099+ - 'invalid_request'
15100+ - 'invalid_grant'
15101+ - 'unsupported_grant_type'
15102+ - 'invalid_scope'
15103+ - 'server_error'
15104+ - 'temporarily_unavailable'
15105+ type: 'string'
15106+ x-speakeasy-unknown-values: allow
15107+ error_description:
15108+ type: 'string'
15109+ required:
15110+ - 'error'
15111+ - 'error_description'
15112+ type: 'object'
15113+ OAuthJwks:
15114+ description: 'RFC 7517 JWK Set of the keys OpenRouter signs access tokens with.'
15115+ example:
15116+ keys:
15117+ - alg: 'ES256'
15118+ crv: 'P-256'
15119+ kid: 'or-2026-09'
15120+ kty: 'EC'
15121+ use: 'sig'
15122+ x: 'f83OJ3D2xF1Bg8vub9tLe1gHMzV76e8Tus9uPHvRVEU'
15123+ 'y': 'x_FEzRu9m36HLN_tue659LNpXW6pCyStikYjKIWI5a0'
15124+ properties:
15125+ keys:
15126+ items:
15127+ additionalProperties: false
15128+ properties:
15129+ alg:
15130+ enum:
15131+ - 'ES256'
15132+ type: 'string'
15133+ crv:
15134+ enum:
15135+ - 'P-256'
15136+ type: 'string'
15137+ kid:
15138+ minLength: 1
15139+ type: 'string'
15140+ kty:
15141+ enum:
15142+ - 'EC'
15143+ type: 'string'
15144+ use:
15145+ enum:
15146+ - 'sig'
15147+ type: 'string'
15148+ x:
15149+ pattern: '^[A-Za-z0-9_-]+$'
15150+ type: 'string'
15151+ 'y':
15152+ pattern: '^[A-Za-z0-9_-]+$'
15153+ type: 'string'
15154+ required:
15155+ - 'kty'
15156+ - 'crv'
15157+ - 'kid'
15158+ - 'x'
15159+ - 'y'
15160+ - 'alg'
15161+ - 'use'
15162+ type: 'object'
15163+ minItems: 1
15164+ type: 'array'
15165+ required:
15166+ - 'keys'
15167+ type: 'object'
1509115168 ObservabilityArizeDestination:
1509215169 example:
1509315170 api_key_hashes: null
@@ -25122,6 +25199,92 @@ components:
2512225199 example:
2512325200 format:
2512425201 type: 'text'
25202+ TokenExchangeRequest:
25203+ description: 'RFC 8693 token exchange request body (application/x-www-form-urlencoded).'
25204+ example:
25205+ federation_policy_id: '4b2f7d1e-8c3a-4e5f-9a6b-1c2d3e4f5a6b'
25206+ grant_type: 'urn:ietf:params:oauth:grant-type:token-exchange'
25207+ subject_token: '<jwt from your identity provider>'
25208+ subject_token_type: 'urn:ietf:params:oauth:token-type:jwt'
25209+ properties:
25210+ federation_policy_id:
25211+ description: 'The federation policy to evaluate, from Settings → Workload identity. Binds the exchange to one organization.'
25212+ example: '4b2f7d1e-8c3a-4e5f-9a6b-1c2d3e4f5a6b'
25213+ format: 'uuid'
25214+ type: 'string'
25215+ grant_type:
25216+ description: 'Must be `urn:ietf:params:oauth:grant-type:token-exchange`.'
25217+ enum:
25218+ - 'urn:ietf:params:oauth:grant-type:token-exchange'
25219+ example: 'urn:ietf:params:oauth:grant-type:token-exchange'
25220+ type: 'string'
25221+ requested_token_type:
25222+ description: 'Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`.'
25223+ enum:
25224+ - 'urn:ietf:params:oauth:token-type:access_token'
25225+ example: 'urn:ietf:params:oauth:token-type:access_token'
25226+ type: 'string'
25227+ scope:
25228+ description: 'Optional; only `inference` is available.'
25229+ enum:
25230+ - 'inference'
25231+ example: 'inference'
25232+ type: 'string'
25233+ subject_token:
25234+ description: 'The JWT issued by your identity provider.'
25235+ example: '<jwt from your identity provider>'
25236+ maxLength: 16384
25237+ minLength: 1
25238+ type: 'string'
25239+ subject_token_type:
25240+ description: 'Must be `urn:ietf:params:oauth:token-type:jwt`.'
25241+ enum:
25242+ - 'urn:ietf:params:oauth:token-type:jwt'
25243+ example: 'urn:ietf:params:oauth:token-type:jwt'
25244+ type: 'string'
25245+ required:
25246+ - 'grant_type'
25247+ - 'subject_token'
25248+ - 'federation_policy_id'
25249+ - 'subject_token_type'
25250+ type: 'object'
25251+ TokenExchangeResponse:
25252+ description: 'RFC 8693 token exchange response.'
25253+ example:
25254+ access_token: '<short-lived openrouter access token jwt>'
25255+ expires_in: 900
25256+ issued_token_type: 'urn:ietf:params:oauth:token-type:access_token'
25257+ scope: 'inference'
25258+ token_type: 'Bearer'
25259+ properties:
25260+ access_token:
25261+ description: 'A short-lived JWT to send as `Authorization: Bearer` to the inference API.'
25262+ example: '<short-lived openrouter access token jwt>'
25263+ type: 'string'
25264+ expires_in:
25265+ description: 'Seconds until the access token expires: at most 15 minutes, and never later than the subject token expires.'
25266+ example: 900
25267+ type: 'integer'
25268+ issued_token_type:
25269+ enum:
25270+ - 'urn:ietf:params:oauth:token-type:access_token'
25271+ example: 'urn:ietf:params:oauth:token-type:access_token'
25272+ type: 'string'
25273+ scope:
25274+ example: 'inference'
25275+ type: 'string'
25276+ token_type:
25277+ enum:
25278+ - 'Bearer'
25279+ example: 'Bearer'
25280+ type: 'string'
25281+ required:
25282+ - 'access_token'
25283+ - 'issued_token_type'
25284+ - 'token_type'
25285+ - 'expires_in'
25286+ - 'scope'
25287+ type: 'object'
2512525288 ToolCallStatus:
2512625289 enum:
2512725290 - 'in_progress'
@@ -36621,6 +36784,78 @@ paths:
3662136784 - $ref: "#/components/parameters/AppIdentifier"
3662236785 - $ref: "#/components/parameters/AppDisplayName"
3662336786 - $ref: "#/components/parameters/AppCategories"
36787+ /oauth/jwks:
36788+ get:
36789+ description: 'RFC 7517 JWK Set containing the public keys OpenRouter signs access tokens with.'
36790+ operationId: 'listOauthJwks'
36791+ responses:
36792+ '200':
36793+ content:
36794+ application/json:
36795+ schema:
36796+ $ref: '#/components/schemas/OAuthJwks'
36797+ description: 'JWK Set'
36798+ '500':
36799+ content:
36800+ application/json:
36801+ schema:
36802+ $ref: '#/components/schemas/InternalServerResponse'
36803+ description: 'Signing keys are not configured'
36804+ summary: 'OpenRouter access token signing keys'
36805+ tags:
36806+ - 'OAuth'
36807+ parameters:
36808+ - $ref: "#/components/parameters/AppIdentifier"
36809+ - $ref: "#/components/parameters/AppDisplayName"
36810+ - $ref: "#/components/parameters/AppCategories"
36811+ /oauth/token:
36812+ post:
36813+ description: 'RFC 8693 token exchange. Presents a JWT from an issuer your organization trusts (Settings → Workload identity) and receives a short-lived OpenRouter access token that acts as the API key the matching federation policy targets.'
36814+ operationId: 'createOauthToken'
36815+ requestBody:
36816+ content:
36817+ application/x-www-form-urlencoded:
36818+ schema:
36819+ $ref: '#/components/schemas/TokenExchangeRequest'
36820+ required: true
36821+ responses:
36822+ '200':
36823+ content:
36824+ application/json:
36825+ schema:
36826+ $ref: '#/components/schemas/TokenExchangeResponse'
36827+ description: 'Access token issued'
36828+ '400':
36829+ content:
36830+ application/json:
36831+ schema:
36832+ $ref: '#/components/schemas/OAuthErrorResponse'
36833+ description: 'Malformed request, unsupported grant, or the subject token was not accepted'
36834+ '429':
36835+ content:
36836+ application/json:
36837+ schema:
36838+ $ref: '#/components/schemas/OAuthErrorResponse'
36839+ description: 'Rate limited'
36840+ '500':
36841+ content:
36842+ application/json:
36843+ schema:
36844+ $ref: '#/components/schemas/OAuthErrorResponse'
36845+ description: 'The token could not be issued'
36846+ '503':
36847+ content:
36848+ application/json:
36849+ schema:
36850+ $ref: '#/components/schemas/OAuthErrorResponse'
36851+ description: 'The issuer’s discovery document or JWKS could not be fetched'
36852+ summary: 'Exchange a workload identity token'
36853+ tags:
36854+ - 'OAuth'
36855+ parameters:
36856+ - $ref: "#/components/parameters/AppIdentifier"
36857+ - $ref: "#/components/parameters/AppDisplayName"
36858+ - $ref: "#/components/parameters/AppCategories"
3662436859 /observability/destinations:
3662536860 get:
3662636861 description: 'List the observability destinations configured for the authenticated entity''s default workspace. Use the `workspace_id` query parameter to scope the result to a different workspace. Only destinations with stable release status are surfaced — destinations of other types are excluded. [Management key](/docs/guides/overview/auth/management-api-keys) required.'
0 commit comments