Skip to main content

Apps and credentials API

An app owns its gateway credentials, stored controls, routing, prompts and configuration history. Manage it by app name within the key's tenant. App deletion is Not Generally Available.

Apps and provider attachments​

Naming and identity​

Names are trimmed and compared case-insensitively. New names must be unique among enabled and disabled apps. A disabled app continues to reserve its name. If multiple legacy apps match a name, the API returns 409 ambiguous_app_name instead of choosing one silently.

For simple names, encode one URL path segment: Support Bot becomes Support%20Bot. For names containing /, % or other proxy-sensitive characters, use /app?app_name=<URL-encoded name>. Every app subresource has this query alias, for example /app/keys?app_name=Team%20%2F%20Support. Encode the query value once. App renaming is Not Generally Available. Changing an individual credential does not change the canonical app or log attribution.

Creating an app​

InputRule
nameRequired display name, 1-200 characters.
modegateway by default; sdk and copilot_studio preserve their existing providerless app modes.
provider_labelsRequired, ordered, nonempty list for gateway apps. First is primary. Omit for providerless modes.
initial_keyOptional. Omission still issues one key named Default. Optional expiry applies to the gateway key, not the management key.
Configuration sectionsSee full configuration input. Omitted controls use existing gateway defaults. Capabilities lists supported fields and modes; it does not return every effective runtime default.

App creation validates configuration without contacting an upstream model. When QuilrQL is already enabled, creation captures an app baseline and can publish an app-scoped allowed-models default for all users. This does not enable authority or edit drafts, and matching tenant policies still apply. See QuilrQL behavior. Model reachability requires an explicit supported model test.

Disable means the whole app​

PATCH enabled:false to prevent newly admitted runtime traffic once the new configuration has propagated. Settings, provider references, keys, prompts and history remain available to management. Setting enabled:true resumes normal authentication, provider and policy checks.

Whole-app availability is independent of QuilrQL. Disabling an app does not become an inactive policy-governed setting, and re-enabling it does not resurrect expired/revoked keys. This is different from disabling just its primary provider.

Attachment and conversion rules​

  • Attach an existing enabled shared provider by label. primary:false preserves the current primary; primary:true deliberately promotes the attachment.
  • provider_labels on an app PATCH replaces the entire ordered selection. Omission preserves it.
  • A detach is app-local and validates remaining routing references and provider selection. While QuilrQL is enabled, provider removal conservatively returns 409 policy_dependency; adding a provider remains supported. Provider-backed apps must keep at least one provider.
  • Legacy inline-provider apps can be read and receive non-provider edits. Provider changes require the explicit conversion endpoint first.
  • Conversion supplies the complete shared-provider selection and optional routing, using the current app ETag. It preserves the app and its keys. It does not create shared providers or publish policy, and it has no idempotent-replay contract.

App endpoints​

Expand Full request body specification for every field, including nested configuration. For a focused view, see the configuration schema.

GET/apps

List apps

Tenant app collection. Creation requires config:write and credentials:write and issues one gateway credential. Existing QuilrQL authority can publish app-specific model-access defaults.

REQUIRESread
Path, query & header parameters 5
limit (query)integeroptional
min: 1max: 200default: 50
cursor (query)stringoptional
name (query)stringoptional

Case-insensitive name substring.

tag (query)stringoptional

Exact tag.

enabled (query)stringoptional

true or false.

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps?limit=50' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

POST/apps

Create an app

Tenant app collection. Creation requires config:write and credentials:write and issues one gateway credential. Existing QuilrQL authority can publish app-specific model-access defaults.

REQUIRESconfig:writecredentials:write
Path, query & header parameters 1
Idempotency-Key (header)stringrequired
min length: 1max length: 200
Full request body specification application/json

Create an app and one gateway credential. Gateway mode requires a nonempty ordered provider_labels list; SDK/Copilot Studio omit it. initial_key defaults to a key named Default. Existing QuilrQL authority can publish the new app allowed-models default.

detectionobjectoptional
Object fields
category_actionsmap<string, string>optional

Category ID to action.

Map value specification
string

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

Values: "monitor""partial-redact""redact""block"

category_scopesmap<string, string>optional
Map value specification
string

Values: "request""response""both"

category_sensitivitiesmap<string, array<string>>optional
Map value specification
array<string>
custom_definitionsarray<object>optional

Full replacement of definition selections; [] removes selections. Does not delete definitions.

max items: 1000
Array item specification
definition_idstringrequired

Stable ID from GET /custom-definitions.

min length: 1max length: 200
enabledbooleanoptional
default: true
actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
scopestringoptional
"request""response""both"
sensitivitystringoptional
"low""medium""high"

Unknown fields are rejected in this object.

data_risk_actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
edm_pattern_sensitivitiesmap<string, string>optional
Map value specification
string

Values: "low""medium""high"

enabled_categoriesmap<string, boolean>optional

Catalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.

Map value specification
boolean
guardian_agentobjectoptional

Partial update of Guardian branches. Set a branch enabled:false to disable it. Model-backed checks follow deployment capability.

Object fields
enabledbooleanoptional
coding_helpersobjectoptional
Object fields
enabledbooleanoptional
dependency_security_checkbooleanoptional
latest_version_suggestionsbooleanoptional
task_adherenceobjectoptional
Object fields
enabledbooleanoptional
actionstringoptional
"nudge""block"
sensitivitystringoptional
"low""medium""high"
agent_purposestringoptional
guardian_agent_promptstringoptional
hallucination_check_actionstringoptional
"block""monitor"
hallucination_check_risk_levelstringoptional
hallucination_check_score_thresholdnumberoptional
min: 0max: 1
is_hallucination_check_enabledbooleanoptional
scan_encoded_imagesbooleanoptional
scan_encoded_images_scopestringoptional
"request""response""both"
scan_imagesbooleanoptional
scan_images_scopestringoptional
"request""response""both"
sub_category_actionsmap<string, map<string, string>>optional

Category ID to subcategory name to action.

Map value specification
map<string, string>
sub_category_sensitivitiesmap<string, map<string, string>>optional
Map value specification
map<string, string>

Unknown fields are rejected in this object.

limitsobjectoptional
Object fields
concurrency_per_minuteinteger | nulloptional
min: 0
model_rate_limitsarray<object>optional
Array item specification
provider_labelstringrequired

Exact, trimmed tenant-wide provider label. Immutable after creation.

min length: 1max length: 200
modelstringrequired

Exact configured model identifier; availability depends on the provider and deployment.

min length: 1max length: 512
timeoutnumber | nulloptional

Seconds.

Variant 1 number
number

Seconds.

min: 0

Also accepts null.

concurrency_per_minuteinteger | nulloptional

Request admissions per 60 seconds, following existing gateway semantics.

Variant 1 integer
integer

Request admissions per 60 seconds, following existing gateway semantics.

min: 0

Also accepts null.

rate_limitobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

token_limitsobject | nulloptional
TokenLimits object
max_per_requestinteger | nulloptional

Maximum input tokens per request; zero disables.

Variant 1 integer
integer

Maximum input tokens per request; zero disables.

min: 0

Also accepts null.

inputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

outputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

Also accepts null.

rate_limitobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

rate_limit_per_minuteintegeroptional
min: 0
timeoutinteger | nulloptional
min: 0
token_limitsobjectoptional
Object fields
max_per_requestinteger | nulloptional

Maximum input tokens per request; zero disables.

Variant 1 integer
integer

Maximum input tokens per request; zero disables.

min: 0

Also accepts null.

inputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

outputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

Unknown fields are rejected in this object.

routingobjectoptional
Object fields
custom_routingarray<object>optional
Array item specification
groupstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""bedrock_runtime"
typestringrequired
"Low_Context_Request""Medium_Context_Request""High_Context_Request"
is_publishedbooleanrequired
modelsarray<object>required
Array item specification
provider_namestringrequired
modelstringrequired
labelstringoptional
credential_sourcestringoptional
routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0
routing_thresholdsobjectoptional

0 <= low_max_words <= medium_max_words.

Object fields
low_max_wordsintegerrequired
min: 0
medium_max_wordsintegerrequired
min: 0

Unknown fields are rejected in this object.

token_based_routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0

Unknown fields are rejected in this object.

accessobjectoptional
Object fields
allowed_source_ipsone of 3 variantsoptional
Variant 1 array<string>
array<string>
Variant 2 object
enabledbooleanoptional
ipsarray<string>optional
Array item specification
string

Unknown fields are rejected in this object.

Also accepts null.

allowed_user_domainsarray<string>optional
max items: 1000
Array item specification
string
allowed_user_emailsarray<string>optional
max items: 1000
Array item specification
string
enforce_conversation_idbooleanoptional
enforce_identitybooleanoptional
identity_header_modebooleanoptional
identity_token_headersarray<string>optional
max items: 1000
Array item specification
string
identity_token_oid_fallbackbooleanoptional
jwt_authobject | nulloptional
JwtAuth object
enabledbooleanoptional
allowed_issuersarray<string>optional
Array item specification
string
allowed_client_idsarray<string>optional
Array item specification
string
public_key_pemstringoptional

RSA public key in PEM format. Required for an enabled configuration; saves do not fetch JWKS URLs.

kidstringoptional

Unknown fields are rejected in this object.

Also accepts null.

Unknown fields are rejected in this object.

transformationsobjectoptional
Object fields
token_savingobjectoptional
Object fields
smart_json_compressionbooleanoptional
html_to_textbooleanoptional
markdown_to_textbooleanoptional
text_compressionbooleanoptional

Unknown fields are rejected in this object.

Unknown fields are rejected in this object.

self_serviceobjectoptional
Object fields
enable_self_servicebooleanoptional
self_serviceobjectoptional

Stored self-service configuration. Access-control roles live inside this object. Omit to preserve; the section itself does not accept null.

Object fields
access_controlobject | nulloptional
Variant 1 object
version1optional
self_service_viewerobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
settings_update_requesterobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
settings_update_directobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
show_api_keyobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
show_logs_for_all_usersobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1

Also accepts null.

Unknown fields are rejected in this object.

promptsobjectoptional
Object fields
require_system_from_storebooleanoptional

Unknown fields are rejected in this object.

enabledbooleanoptional
smart_group_policiesarray<object>optional
Array item specification
enabled_categoriesmap<string, boolean>optional

Catalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.

Map value specification
boolean
category_actionsmap<string, string>optional

Category ID to action.

Map value specification
string

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

Values: "monitor""partial-redact""redact""block"

sub_category_actionsmap<string, map<string, string>>optional

Category ID to subcategory name to action.

Map value specification
map<string, string>
category_scopesmap<string, string>optional
Map value specification
string

Values: "request""response""both"

category_sensitivitiesmap<string, array<string>>optional
Map value specification
array<string>
group_namestringrequired
enabledbooleanoptional
actionsobjectoptional
Object fields
data_risk_actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
hallucination_check_actionstringoptional
"block""monitor"
sub_category_sensitivitiesmap<string, map<string, string>>optional
Map value specification
map<string, string>

Unknown fields are rejected in this object.

alertingobject | nulloptional
Alerting object
app_levelobjectoptional
Object fields
enabledbooleanoptional
default: false
window_minutesintegeroptional
min: 5max: 1440default: 15
failure_rate_thresholdnumberoptional

Percentage.

min: 0max: 100default: 10
minimum_requestsintegeroptional
min: 0default: 20
cooldown_minutesintegeroptional
min: 1default: 10
notify_on_recoverybooleanoptional
default: true
provider_levelobjectoptional
Object fields
enabledbooleanoptional
default: false
window_minutesintegeroptional
min: 5max: 1440default: 15
failure_rate_thresholdnumberoptional

Percentage.

min: 0max: 100default: 10
minimum_requestsintegeroptional
min: 0default: 20
cooldown_minutesintegeroptional
min: 1default: 10
notify_on_recoverybooleanoptional
default: true
channelsobjectoptional
Object fields
emailsarray<string>optional
unique items
Array item specification
string
format: email
webhooksarray<object>optional
Array item specification
idstringoptional
min length: 1
typestringoptional
default: "generic"
"slack""generic"
labelstringoptional
urlstringrequired

HTTPS webhook URL, required for each submitted webhook. Omit the whole alerting field to preserve stored configuration.

format: uriwrite only

Also accepts null.

provider_labelsarray<string>optional
max items: 1000
Array item specification
string
tagsarray<string>optional
max items: 1000
Array item specification
string
namestringrequired
min length: 1max length: 200
modestringoptional
default: "gateway"
"gateway""sdk""copilot_studio"
initial_keyobjectoptional
Object fields
namestringoptional
min length: 1max length: 200
expires_atstring | nulloptional
format: date-time

Unknown fields are rejected in this object.

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/apps' \
--header 'Authorization: Bearer <management-key>' \
--header 'Idempotency-Key: unique-operation-001' \
--header 'Content-Type: application/json' \
--data '{
"name": "Support Bot",
"provider_labels": [
"Production OpenAI"
],
"tags": [
"production"
]
}'

Authentication, errors & retry rules

GET/apps/{app_name}

Read an app

Read or update stored settings. App enablement is enforced independently of QuilrQL.

REQUIRESread
Path, query & header parameters 1
app_name (path)stringrequired

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

PATCH/apps/{app_name}

Update or disable an app

Read or update stored settings. App enablement is enforced independently of QuilrQL.

REQUIRESconfig:write
Path, query & header parameters 2
app_name (path)stringrequired
If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

Stored app settings. Omitted fields are preserved. Unknown top-level and section fields are rejected. Nested controls follow the existing gateway validators. Responses report settings that are inactive under QuilrQL.

detectionobjectoptional
Object fields
category_actionsmap<string, string>optional

Category ID to action.

Map value specification
string

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

Values: "monitor""partial-redact""redact""block"

category_scopesmap<string, string>optional
Map value specification
string

Values: "request""response""both"

category_sensitivitiesmap<string, array<string>>optional
Map value specification
array<string>
custom_definitionsarray<object>optional

Full replacement of definition selections; [] removes selections. Does not delete definitions.

max items: 1000
Array item specification
definition_idstringrequired

Stable ID from GET /custom-definitions.

min length: 1max length: 200
enabledbooleanoptional
default: true
actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
scopestringoptional
"request""response""both"
sensitivitystringoptional
"low""medium""high"

Unknown fields are rejected in this object.

data_risk_actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
edm_pattern_sensitivitiesmap<string, string>optional
Map value specification
string

Values: "low""medium""high"

enabled_categoriesmap<string, boolean>optional

Catalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.

Map value specification
boolean
guardian_agentobjectoptional

Partial update of Guardian branches. Set a branch enabled:false to disable it. Model-backed checks follow deployment capability.

Object fields
enabledbooleanoptional
coding_helpersobjectoptional
Object fields
enabledbooleanoptional
dependency_security_checkbooleanoptional
latest_version_suggestionsbooleanoptional
task_adherenceobjectoptional
Object fields
enabledbooleanoptional
actionstringoptional
"nudge""block"
sensitivitystringoptional
"low""medium""high"
agent_purposestringoptional
guardian_agent_promptstringoptional
hallucination_check_actionstringoptional
"block""monitor"
hallucination_check_risk_levelstringoptional
hallucination_check_score_thresholdnumberoptional
min: 0max: 1
is_hallucination_check_enabledbooleanoptional
scan_encoded_imagesbooleanoptional
scan_encoded_images_scopestringoptional
"request""response""both"
scan_imagesbooleanoptional
scan_images_scopestringoptional
"request""response""both"
sub_category_actionsmap<string, map<string, string>>optional

Category ID to subcategory name to action.

Map value specification
map<string, string>
sub_category_sensitivitiesmap<string, map<string, string>>optional
Map value specification
map<string, string>

Unknown fields are rejected in this object.

limitsobjectoptional
Object fields
concurrency_per_minuteinteger | nulloptional
min: 0
model_rate_limitsarray<object>optional
Array item specification
provider_labelstringrequired

Exact, trimmed tenant-wide provider label. Immutable after creation.

min length: 1max length: 200
modelstringrequired

Exact configured model identifier; availability depends on the provider and deployment.

min length: 1max length: 512
timeoutnumber | nulloptional

Seconds.

Variant 1 number
number

Seconds.

min: 0

Also accepts null.

concurrency_per_minuteinteger | nulloptional

Request admissions per 60 seconds, following existing gateway semantics.

Variant 1 integer
integer

Request admissions per 60 seconds, following existing gateway semantics.

min: 0

Also accepts null.

rate_limitobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

token_limitsobject | nulloptional
TokenLimits object
max_per_requestinteger | nulloptional

Maximum input tokens per request; zero disables.

Variant 1 integer
integer

Maximum input tokens per request; zero disables.

min: 0

Also accepts null.

inputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

outputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

Also accepts null.

rate_limitobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

rate_limit_per_minuteintegeroptional
min: 0
timeoutinteger | nulloptional
min: 0
token_limitsobjectoptional
Object fields
max_per_requestinteger | nulloptional

Maximum input tokens per request; zero disables.

Variant 1 integer
integer

Maximum input tokens per request; zero disables.

min: 0

Also accepts null.

inputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

outputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

Unknown fields are rejected in this object.

routingobjectoptional
Object fields
custom_routingarray<object>optional
Array item specification
groupstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""bedrock_runtime"
typestringrequired
"Low_Context_Request""Medium_Context_Request""High_Context_Request"
is_publishedbooleanrequired
modelsarray<object>required
Array item specification
provider_namestringrequired
modelstringrequired
labelstringoptional
credential_sourcestringoptional
routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0
routing_thresholdsobjectoptional

0 <= low_max_words <= medium_max_words.

Object fields
low_max_wordsintegerrequired
min: 0
medium_max_wordsintegerrequired
min: 0

Unknown fields are rejected in this object.

token_based_routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0

Unknown fields are rejected in this object.

accessobjectoptional
Object fields
allowed_source_ipsone of 3 variantsoptional
Variant 1 array<string>
array<string>
Variant 2 object
enabledbooleanoptional
ipsarray<string>optional
Array item specification
string

Unknown fields are rejected in this object.

Also accepts null.

allowed_user_domainsarray<string>optional
max items: 1000
Array item specification
string
allowed_user_emailsarray<string>optional
max items: 1000
Array item specification
string
enforce_conversation_idbooleanoptional
enforce_identitybooleanoptional
identity_header_modebooleanoptional
identity_token_headersarray<string>optional
max items: 1000
Array item specification
string
identity_token_oid_fallbackbooleanoptional
jwt_authobject | nulloptional
JwtAuth object
enabledbooleanoptional
allowed_issuersarray<string>optional
Array item specification
string
allowed_client_idsarray<string>optional
Array item specification
string
public_key_pemstringoptional

RSA public key in PEM format. Required for an enabled configuration; saves do not fetch JWKS URLs.

kidstringoptional

Unknown fields are rejected in this object.

Also accepts null.

Unknown fields are rejected in this object.

transformationsobjectoptional
Object fields
token_savingobjectoptional
Object fields
smart_json_compressionbooleanoptional
html_to_textbooleanoptional
markdown_to_textbooleanoptional
text_compressionbooleanoptional

Unknown fields are rejected in this object.

Unknown fields are rejected in this object.

self_serviceobjectoptional
Object fields
enable_self_servicebooleanoptional
self_serviceobjectoptional

Stored self-service configuration. Access-control roles live inside this object. Omit to preserve; the section itself does not accept null.

Object fields
access_controlobject | nulloptional
Variant 1 object
version1optional
self_service_viewerobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
settings_update_requesterobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
settings_update_directobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
show_api_keyobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
show_logs_for_all_usersobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1

Also accepts null.

Unknown fields are rejected in this object.

promptsobjectoptional
Object fields
require_system_from_storebooleanoptional

Unknown fields are rejected in this object.

enabledbooleanoptional
smart_group_policiesarray<object>optional
Array item specification
enabled_categoriesmap<string, boolean>optional

Catalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.

Map value specification
boolean
category_actionsmap<string, string>optional

Category ID to action.

Map value specification
string

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

Values: "monitor""partial-redact""redact""block"

sub_category_actionsmap<string, map<string, string>>optional

Category ID to subcategory name to action.

Map value specification
map<string, string>
category_scopesmap<string, string>optional
Map value specification
string

Values: "request""response""both"

category_sensitivitiesmap<string, array<string>>optional
Map value specification
array<string>
group_namestringrequired
enabledbooleanoptional
actionsobjectoptional
Object fields
data_risk_actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
hallucination_check_actionstringoptional
"block""monitor"
sub_category_sensitivitiesmap<string, map<string, string>>optional
Map value specification
map<string, string>

Unknown fields are rejected in this object.

alertingobject | nulloptional
Alerting object
app_levelobjectoptional
Object fields
enabledbooleanoptional
default: false
window_minutesintegeroptional
min: 5max: 1440default: 15
failure_rate_thresholdnumberoptional

Percentage.

min: 0max: 100default: 10
minimum_requestsintegeroptional
min: 0default: 20
cooldown_minutesintegeroptional
min: 1default: 10
notify_on_recoverybooleanoptional
default: true
provider_levelobjectoptional
Object fields
enabledbooleanoptional
default: false
window_minutesintegeroptional
min: 5max: 1440default: 15
failure_rate_thresholdnumberoptional

Percentage.

min: 0max: 100default: 10
minimum_requestsintegeroptional
min: 0default: 20
cooldown_minutesintegeroptional
min: 1default: 10
notify_on_recoverybooleanoptional
default: true
channelsobjectoptional
Object fields
emailsarray<string>optional
unique items
Array item specification
string
format: email
webhooksarray<object>optional
Array item specification
idstringoptional
min length: 1
typestringoptional
default: "generic"
"slack""generic"
labelstringoptional
urlstringrequired

HTTPS webhook URL, required for each submitted webhook. Omit the whole alerting field to preserve stored configuration.

format: uriwrite only

Also accepts null.

provider_labelsarray<string>optional
max items: 1000
Array item specification
string
tagsarray<string>optional
max items: 1000
Array item specification
string

Unknown fields are rejected in this object.

curl --request PATCH \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"detection": {
"data_risk_action": "redact"
},
"limits": {
"timeout": 30
}
}'

Authentication, errors & retry rules

GET/apps/{app_name}/providers

List app providers

Returns ordered provider_labels and the app version, not a paginated provider collection.

REQUIRESread
Path, query & header parameters 1
app_name (path)stringrequired

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/providers' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

PUT/apps/{app_name}/providers/{label}

Attach a shared provider

Use the current app ETag. PUT preserves unrelated attachments; DELETE validates remaining routes. Provider removal while QuilrQL is enabled returns policy_dependency.

REQUIRESconfig:write
Path, query & header parameters 3
app_name (path)stringrequired
label (path)stringrequired
If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

primarybooleanoptional
default: false

Unknown fields are rejected in this object.

curl --request PUT \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/providers/Production%20OpenAI' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"primary": false
}'

Authentication, errors & retry rules

DELETE/apps/{app_name}/providers/{label}

Detach an app provider

Use the current app ETag. PUT preserves unrelated attachments; DELETE validates remaining routes. Provider removal while QuilrQL is enabled returns policy_dependency.

REQUIRESconfig:write
Path, query & header parameters 3
app_name (path)stringrequired
label (path)stringrequired
If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

Unknown fields are rejected in this object.

curl --request DELETE \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/providers/Production%20OpenAI' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{}'

Authentication, errors & retry rules

POST/apps/{app_name}/provider-conversion

Convert inline providers

Convert an inline app using a complete shared-provider selection. Uses the app ETag; no idempotency replay contract.

REQUIRESconfig:write
Path, query & header parameters 2
app_name (path)stringrequired
If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

provider_labelsarray<string>required
max items: 1000
Array item specification
string
routingobjectoptional
Object fields
custom_routingarray<object>optional
Array item specification
groupstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""bedrock_runtime"
typestringrequired
"Low_Context_Request""Medium_Context_Request""High_Context_Request"
is_publishedbooleanrequired
modelsarray<object>required
Array item specification
provider_namestringrequired
modelstringrequired
labelstringoptional
credential_sourcestringoptional
routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0
routing_thresholdsobjectoptional

0 <= low_max_words <= medium_max_words.

Object fields
low_max_wordsintegerrequired
min: 0
medium_max_wordsintegerrequired
min: 0

Unknown fields are rejected in this object.

token_based_routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0

Unknown fields are rejected in this object.

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/provider-conversion' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"provider_labels": [
"Production OpenAI"
]
}'

Authentication, errors & retry rules

GET/app

Read an app (query locator)

Read or update stored settings. App enablement is enforced independently of QuilrQL. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESread
Path, query & header parameters 1
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/app?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

PATCH/app

Update or disable an app (query locator)

Read or update stored settings. App enablement is enforced independently of QuilrQL. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESconfig:write
Path, query & header parameters 2
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

Stored app settings. Omitted fields are preserved. Unknown top-level and section fields are rejected. Nested controls follow the existing gateway validators. Responses report settings that are inactive under QuilrQL.

detectionobjectoptional
Object fields
category_actionsmap<string, string>optional

Category ID to action.

Map value specification
string

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

Values: "monitor""partial-redact""redact""block"

category_scopesmap<string, string>optional
Map value specification
string

Values: "request""response""both"

category_sensitivitiesmap<string, array<string>>optional
Map value specification
array<string>
custom_definitionsarray<object>optional

Full replacement of definition selections; [] removes selections. Does not delete definitions.

max items: 1000
Array item specification
definition_idstringrequired

Stable ID from GET /custom-definitions.

min length: 1max length: 200
enabledbooleanoptional
default: true
actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
scopestringoptional
"request""response""both"
sensitivitystringoptional
"low""medium""high"

Unknown fields are rejected in this object.

data_risk_actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
edm_pattern_sensitivitiesmap<string, string>optional
Map value specification
string

Values: "low""medium""high"

enabled_categoriesmap<string, boolean>optional

Catalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.

Map value specification
boolean
guardian_agentobjectoptional

Partial update of Guardian branches. Set a branch enabled:false to disable it. Model-backed checks follow deployment capability.

Object fields
enabledbooleanoptional
coding_helpersobjectoptional
Object fields
enabledbooleanoptional
dependency_security_checkbooleanoptional
latest_version_suggestionsbooleanoptional
task_adherenceobjectoptional
Object fields
enabledbooleanoptional
actionstringoptional
"nudge""block"
sensitivitystringoptional
"low""medium""high"
agent_purposestringoptional
guardian_agent_promptstringoptional
hallucination_check_actionstringoptional
"block""monitor"
hallucination_check_risk_levelstringoptional
hallucination_check_score_thresholdnumberoptional
min: 0max: 1
is_hallucination_check_enabledbooleanoptional
scan_encoded_imagesbooleanoptional
scan_encoded_images_scopestringoptional
"request""response""both"
scan_imagesbooleanoptional
scan_images_scopestringoptional
"request""response""both"
sub_category_actionsmap<string, map<string, string>>optional

Category ID to subcategory name to action.

Map value specification
map<string, string>
sub_category_sensitivitiesmap<string, map<string, string>>optional
Map value specification
map<string, string>

Unknown fields are rejected in this object.

limitsobjectoptional
Object fields
concurrency_per_minuteinteger | nulloptional
min: 0
model_rate_limitsarray<object>optional
Array item specification
provider_labelstringrequired

Exact, trimmed tenant-wide provider label. Immutable after creation.

min length: 1max length: 200
modelstringrequired

Exact configured model identifier; availability depends on the provider and deployment.

min length: 1max length: 512
timeoutnumber | nulloptional

Seconds.

Variant 1 number
number

Seconds.

min: 0

Also accepts null.

concurrency_per_minuteinteger | nulloptional

Request admissions per 60 seconds, following existing gateway semantics.

Variant 1 integer
integer

Request admissions per 60 seconds, following existing gateway semantics.

min: 0

Also accepts null.

rate_limitobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

token_limitsobject | nulloptional
TokenLimits object
max_per_requestinteger | nulloptional

Maximum input tokens per request; zero disables.

Variant 1 integer
integer

Maximum input tokens per request; zero disables.

min: 0

Also accepts null.

inputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

outputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

Also accepts null.

rate_limitobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

rate_limit_per_minuteintegeroptional
min: 0
timeoutinteger | nulloptional
min: 0
token_limitsobjectoptional
Object fields
max_per_requestinteger | nulloptional

Maximum input tokens per request; zero disables.

Variant 1 integer
integer

Maximum input tokens per request; zero disables.

min: 0

Also accepts null.

inputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

outputobject | nulloptional
RateLimit object
valueintegerrequired

Maximum events in the window; zero disables this limit.

min: 0
durationstringrequired
"minute""hour""day"

Also accepts null.

Unknown fields are rejected in this object.

routingobjectoptional
Object fields
custom_routingarray<object>optional
Array item specification
groupstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""bedrock_runtime"
typestringrequired
"Low_Context_Request""Medium_Context_Request""High_Context_Request"
is_publishedbooleanrequired
modelsarray<object>required
Array item specification
provider_namestringrequired
modelstringrequired
labelstringoptional
credential_sourcestringoptional
routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0
routing_thresholdsobjectoptional

0 <= low_max_words <= medium_max_words.

Object fields
low_max_wordsintegerrequired
min: 0
medium_max_wordsintegerrequired
min: 0

Unknown fields are rejected in this object.

token_based_routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0

Unknown fields are rejected in this object.

accessobjectoptional
Object fields
allowed_source_ipsone of 3 variantsoptional
Variant 1 array<string>
array<string>
Variant 2 object
enabledbooleanoptional
ipsarray<string>optional
Array item specification
string

Unknown fields are rejected in this object.

Also accepts null.

allowed_user_domainsarray<string>optional
max items: 1000
Array item specification
string
allowed_user_emailsarray<string>optional
max items: 1000
Array item specification
string
enforce_conversation_idbooleanoptional
enforce_identitybooleanoptional
identity_header_modebooleanoptional
identity_token_headersarray<string>optional
max items: 1000
Array item specification
string
identity_token_oid_fallbackbooleanoptional
jwt_authobject | nulloptional
JwtAuth object
enabledbooleanoptional
allowed_issuersarray<string>optional
Array item specification
string
allowed_client_idsarray<string>optional
Array item specification
string
public_key_pemstringoptional

RSA public key in PEM format. Required for an enabled configuration; saves do not fetch JWKS URLs.

kidstringoptional

Unknown fields are rejected in this object.

Also accepts null.

Unknown fields are rejected in this object.

transformationsobjectoptional
Object fields
token_savingobjectoptional
Object fields
smart_json_compressionbooleanoptional
html_to_textbooleanoptional
markdown_to_textbooleanoptional
text_compressionbooleanoptional

Unknown fields are rejected in this object.

Unknown fields are rejected in this object.

self_serviceobjectoptional
Object fields
enable_self_servicebooleanoptional
self_serviceobjectoptional

Stored self-service configuration. Access-control roles live inside this object. Omit to preserve; the section itself does not accept null.

Object fields
access_controlobject | nulloptional
Variant 1 object
version1optional
self_service_viewerobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
settings_update_requesterobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
settings_update_directobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
show_api_keyobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
show_logs_for_all_usersobjectoptional

Deny rules win. A group reference never changes group membership.

Object fields
allow_allbooleanoptional
default: false
allow_emailsarray<string>optional
unique items
Array item specification
string
format: email
deny_emailsarray<string>optional
unique items
Array item specification
string
format: email
allow_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1
deny_smart_groupsarray<string>optional
unique items
Array item specification
string

Existing gateway smart-group name.

min length: 1

Also accepts null.

Unknown fields are rejected in this object.

promptsobjectoptional
Object fields
require_system_from_storebooleanoptional

Unknown fields are rejected in this object.

enabledbooleanoptional
smart_group_policiesarray<object>optional
Array item specification
enabled_categoriesmap<string, boolean>optional

Catalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.

Map value specification
boolean
category_actionsmap<string, string>optional

Category ID to action.

Map value specification
string

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

Values: "monitor""partial-redact""redact""block"

sub_category_actionsmap<string, map<string, string>>optional

Category ID to subcategory name to action.

Map value specification
map<string, string>
category_scopesmap<string, string>optional
Map value specification
string

Values: "request""response""both"

category_sensitivitiesmap<string, array<string>>optional
Map value specification
array<string>
group_namestringrequired
enabledbooleanoptional
actionsobjectoptional
Object fields
data_risk_actionstringoptional

Adversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.

"monitor""partial-redact""redact""block"
hallucination_check_actionstringoptional
"block""monitor"
sub_category_sensitivitiesmap<string, map<string, string>>optional
Map value specification
map<string, string>

Unknown fields are rejected in this object.

alertingobject | nulloptional
Alerting object
app_levelobjectoptional
Object fields
enabledbooleanoptional
default: false
window_minutesintegeroptional
min: 5max: 1440default: 15
failure_rate_thresholdnumberoptional

Percentage.

min: 0max: 100default: 10
minimum_requestsintegeroptional
min: 0default: 20
cooldown_minutesintegeroptional
min: 1default: 10
notify_on_recoverybooleanoptional
default: true
provider_levelobjectoptional
Object fields
enabledbooleanoptional
default: false
window_minutesintegeroptional
min: 5max: 1440default: 15
failure_rate_thresholdnumberoptional

Percentage.

min: 0max: 100default: 10
minimum_requestsintegeroptional
min: 0default: 20
cooldown_minutesintegeroptional
min: 1default: 10
notify_on_recoverybooleanoptional
default: true
channelsobjectoptional
Object fields
emailsarray<string>optional
unique items
Array item specification
string
format: email
webhooksarray<object>optional
Array item specification
idstringoptional
min length: 1
typestringoptional
default: "generic"
"slack""generic"
labelstringoptional
urlstringrequired

HTTPS webhook URL, required for each submitted webhook. Omit the whole alerting field to preserve stored configuration.

format: uriwrite only

Also accepts null.

provider_labelsarray<string>optional
max items: 1000
Array item specification
string
tagsarray<string>optional
max items: 1000
Array item specification
string

Unknown fields are rejected in this object.

curl --request PATCH \
'https://management.example.com/llmgateway/management/v1/app?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"detection": {
"data_risk_action": "redact"
},
"limits": {
"timeout": 30
}
}'

Authentication, errors & retry rules

GET/app/providers

List app providers (query locator)

Returns ordered provider_labels and the app version, not a paginated provider collection. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESread
Path, query & header parameters 1
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/app/providers?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

PUT/app/providers/{label}

Attach a shared provider (query locator)

Use the current app ETag. PUT preserves unrelated attachments; DELETE validates remaining routes. Provider removal while QuilrQL is enabled returns policy_dependency. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESconfig:write
Path, query & header parameters 3
label (path)stringrequired
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

primarybooleanoptional
default: false

Unknown fields are rejected in this object.

curl --request PUT \
'https://management.example.com/llmgateway/management/v1/app/providers/Production%20OpenAI?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"primary": false
}'

Authentication, errors & retry rules

DELETE/app/providers/{label}

Detach an app provider (query locator)

Use the current app ETag. PUT preserves unrelated attachments; DELETE validates remaining routes. Provider removal while QuilrQL is enabled returns policy_dependency. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESconfig:write
Path, query & header parameters 3
label (path)stringrequired
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

Unknown fields are rejected in this object.

curl --request DELETE \
'https://management.example.com/llmgateway/management/v1/app/providers/Production%20OpenAI?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{}'

Authentication, errors & retry rules

POST/app/provider-conversion

Convert inline providers (query locator)

Convert an inline app using a complete shared-provider selection. Uses the app ETag; no idempotency replay contract. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESconfig:write
Path, query & header parameters 2
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

provider_labelsarray<string>required
max items: 1000
Array item specification
string
routingobjectoptional
Object fields
custom_routingarray<object>optional
Array item specification
groupstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""bedrock_runtime"
typestringrequired
"Low_Context_Request""Medium_Context_Request""High_Context_Request"
is_publishedbooleanrequired
modelsarray<object>required
Array item specification
provider_namestringrequired
modelstringrequired
labelstringoptional
credential_sourcestringoptional
routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0
routing_thresholdsobjectoptional

0 <= low_max_words <= medium_max_words.

Object fields
low_max_wordsintegerrequired
min: 0
medium_max_wordsintegerrequired
min: 0

Unknown fields are rejected in this object.

token_based_routing_groupsarray<object>optional
Array item specification
group_namestringrequired
group_kindstringoptional
"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"
modelsarray<object>required
min items: 1
Array item specification
provider_namestringrequired
model_namestringrequired
credential_sourcestringoptional

Attached shared-provider label; no inline credentials.

weightnumberrequired
greater than: 0

Unknown fields are rejected in this object.

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/app/provider-conversion?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"provider_labels": [
"Production OpenAI"
]
}'

Authentication, errors & retry rules

Gateway app credentials​

An app can have multiple named gateway credentials. They share the same app controls, limits, prompts and log identity. Issuing or revoking a credential does not create another app.

Credential contract​

PropertyRule
Initial credentialApp creation always issues one, named Default unless overridden.
Additional credentialsRequire a display name and credentials:write.
NamesTrimmed, 1-120 characters, unique case-insensitively among non-revoked keys of the app.
ExpiryOptional RFC 3339 timestamp. Omitted/null creation expiry means no expiry.
Changing expiryActive credentials only; null clears expiry. Name changes are not supported.
RevocationPreserves history and releases the name. Other valid keys still work.
ListingMetadata/fingerprints only.
RevealingExplicit credentials:read; response is not cacheable. Only active keys can be retrieved. Expired/revoked-key reveal is Not Generally Available and returns 409 terminal_key_state.

Whole-app disable overrides every credential without revoking it. On re-enable, only credentials still valid under expiry/revocation checks work again. JWT/self-service identity follows its own runtime authentication rules.

Rotate without changing the app​

Issue
Create a second named key
Migrate
Move callers to the new key
Revoke
Revoke the old credential
QuilrAI

A dedicated rotation operation is Not Generally Available; the issue/migrate/revoke workflow above is supported. Retain the new credential in your secret store. credentials:write lets an issuer receive a newly created key, but it does not grant permission to reveal every existing key. Management-key issuance and retrieval follow a different administration contract.

GET an individual key to obtain its metadata and version; use that quoted version for PATCH/DELETE. Revocation returns 200 with the updated key and version. Request expires_at and returned gateway-key expiry use RFC 3339; null means no expiry.

Credential endpoints​

GET/apps/{app_name}/keys

List gateway credentials

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.

REQUIRESread
Path, query & header parameters 3
app_name (path)stringrequired
limit (query)integeroptional
min: 1max: 200default: 50
cursor (query)stringoptional

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/keys?limit=50' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

POST/apps/{app_name}/keys

Issue a gateway credential

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.

REQUIREScredentials:write
Path, query & header parameters 2
app_name (path)stringrequired
Idempotency-Key (header)stringrequired
min length: 1max length: 200
Full request body specification application/json

namestringrequired
min length: 1max length: 200
expires_atstring | nulloptional
format: date-time

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/keys' \
--header 'Authorization: Bearer <management-key>' \
--header 'Idempotency-Key: unique-operation-001' \
--header 'Content-Type: application/json' \
--data '{
"name": "Deployment",
"expires_at": null
}'

Authentication, errors & retry rules

GET/apps/{app_name}/keys/{key_id}

Get key

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.

REQUIRESread
Path, query & header parameters 2
app_name (path)stringrequired
key_id (path)stringrequired

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/keys/key_example' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

PATCH/apps/{app_name}/keys/{key_id}

Change gateway key expiry

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.

REQUIREScredentials:write
Path, query & header parameters 3
app_name (path)stringrequired
key_id (path)stringrequired
If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

expires_atstring | nullrequired
format: date-time

Unknown fields are rejected in this object.

curl --request PATCH \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/keys/key_example' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"expires_at": null
}'

Authentication, errors & retry rules

DELETE/apps/{app_name}/keys/{key_id}

Revoke a gateway credential

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.

REQUIREScredentials:write
Path, query & header parameters 3
app_name (path)stringrequired
key_id (path)stringrequired
If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

Unknown fields are rejected in this object.

curl --request DELETE \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/keys/key_example' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{}'

Authentication, errors & retry rules

POST/apps/{app_name}/keys/{key_id}/reveal

Reveal a gateway credential

Explicitly reveal an active gateway credential. Expired/revoked credentials return terminal_key_state.

REQUIREScredentials:read
Path, query & header parameters 2
app_name (path)stringrequired
key_id (path)stringrequired
Full request body specification application/json

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/keys/key_example/reveal' \
--header 'Authorization: Bearer <management-key>' \
--header 'Content-Type: application/json' \
--data '{}'

Authentication, errors & retry rules

GET/app/keys

List gateway credentials (query locator)

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESread
Path, query & header parameters 3
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

limit (query)integeroptional
min: 1max: 200default: 50
cursor (query)stringoptional

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/app/keys?app_name=Support%20Bot&limit=50' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

POST/app/keys

Issue a gateway credential (query locator)

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIREScredentials:write
Path, query & header parameters 2
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

Idempotency-Key (header)stringrequired
min length: 1max length: 200
Full request body specification application/json

namestringrequired
min length: 1max length: 200
expires_atstring | nulloptional
format: date-time

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/app/keys?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'Idempotency-Key: unique-operation-001' \
--header 'Content-Type: application/json' \
--data '{
"name": "Deployment",
"expires_at": null
}'

Authentication, errors & retry rules

GET/app/keys/{key_id}

Get key (query locator)

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIRESread
Path, query & header parameters 2
key_id (path)stringrequired
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

No request body.

curl --request GET \
'https://management.example.com/llmgateway/management/v1/app/keys/key_example?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>'

Authentication, errors & retry rules

PATCH/app/keys/{key_id}

Change gateway key expiry (query locator)

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIREScredentials:write
Path, query & header parameters 3
key_id (path)stringrequired
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

expires_atstring | nullrequired
format: date-time

Unknown fields are rejected in this object.

curl --request PATCH \
'https://management.example.com/llmgateway/management/v1/app/keys/key_example?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"expires_at": null
}'

Authentication, errors & retry rules

DELETE/app/keys/{key_id}

Revoke a gateway credential (query locator)

Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIREScredentials:write
Path, query & header parameters 3
key_id (path)stringrequired
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

If-Match (header)stringrequired

Quoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.

Full request body specification application/json

Unknown fields are rejected in this object.

curl --request DELETE \
'https://management.example.com/llmgateway/management/v1/app/keys/key_example?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{}'

Authentication, errors & retry rules

POST/app/keys/{key_id}/reveal

Reveal a gateway credential (query locator)

Explicitly reveal an active gateway credential. Expired/revoked credentials return terminal_key_state. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.

REQUIREScredentials:read
Path, query & header parameters 2
key_id (path)stringrequired
app_name (query)stringrequired

Exact display name; encode with standard query URL encoding.

Full request body specification application/json

Unknown fields are rejected in this object.

curl --request POST \
'https://management.example.com/llmgateway/management/v1/app/keys/key_example/reveal?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'Content-Type: application/json' \
--data '{}'

Authentication, errors & retry rules