key | str | :heavy_check_mark: | The raw provider API key or credential. This value is encrypted at rest and never returned in API responses. | sk-proj-abc123… |
provider | components.BYOKProviderSlug | :heavy_check_mark: | The upstream provider this credential authenticates against, as a lowercase slug (e.g. openai, anthropic, amazon-bedrock). | openai |
http_referer | Optional[str] | :heavy_minus_sign: | The app identifier should be your app’s URL and is used as the primary identifier for rankings. This is used to track API usage per application.
| |
x_open_router_title | Optional[str] | :heavy_minus_sign: | The app display name allows you to customize how your app appears in OpenRouter’s dashboard.
| |
x_open_router_categories | Optional[str] | :heavy_minus_sign: | Comma-separated list of app categories (e.g. “cli-agent,cloud-agent”). Used for marketplace rankings.
| |
allowed_api_key_hashes | List[str] | :heavy_minus_sign: | Optional allowlist of OpenRouter API key hashes (api_keys.hash) that may use this credential. null means no restriction. Must contain at least one hash if provided. Hashes that do not belong to your account return a 400. | [ “f01d52606dc8f0a8303a7b5cc3fa07109c2e346cec7c0a16b40de462992ce943” ] |
allowed_models | List[str] | :heavy_minus_sign: | Optional allowlist of model slugs this credential may be used for. null means no restriction. | null |
allowed_user_ids | List[str] | :heavy_minus_sign: | Optional allowlist of user IDs that may use this credential. null means no restriction. | null |
disabled | Optional[bool] | :heavy_minus_sign: | Whether this credential should be created in a disabled state. | false |
is_byok_only | Optional[bool] | :heavy_minus_sign: | Whether OpenRouter’s shared endpoints on this provider are removed for every model, including models outside allowed_models and after all of your keys for the provider fail. The provider is skipped instead of spending OpenRouter credits. Only valid on non-fallback credentials. Defaults to false. | false |
is_fallback | Optional[bool] | :heavy_minus_sign: | Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried. Cannot be combined with is_byok_only. | false |
is_required | Optional[bool] | :heavy_minus_sign: | Whether OpenRouter’s shared endpoints on this provider are removed for the models this credential applies to (its allowed_models, or every model when null). Requests for those models run only on your keys; models outside the allowlist may still fall back to shared capacity on this provider. Defaults to false. | false |
name | OptionalNullable[str] | :heavy_minus_sign: | Optional human-readable name for the credential. | Production OpenAI Key |
workspace_id | Optional[str] | :heavy_minus_sign: | Optional workspace ID to scope the credential to. When omitted, the credential is created in the account’s default workspace; if that default has been deleted, the request returns a 400 and you must pass workspace_id explicitly. | 550e8400-e29b-41d4-a716-446655440000 |
retries | Optional[utils.RetryConfig] | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | |