Providers and configuration API
A shared provider is a reusable tenant-owned connection. Apps hold references to its label, so credential/model changes can affect every linked app after synchronization. Provider label and type are immutable.
Shared providers and model tests
Provider inputs
Creation requires label, provider_name and credentials for the selected provider type in provider_settings. Optional selected_models, model_costs and enabled configure availability. Use the provider-settings field reference below and the credential requirements for your provider family. Managed QuilrAI providers do not require customer credentials.
SDK and Copilot Studio are app modes, not shared-provider types. Provider/protocol support remains deployment-dependent. See provider support.
Models and rates
selected_models is a full replacement list, with at most 1,000 names of up to 512 characters each. An empty list follows the existing unrestricted-provider convention where supported; it does not necessarily mean zero models are allowed. Use explicit model lists for finite allowlists.
model_costs is keyed by a selected model. Values are nullable, non-negative USD rates per million input/output/cache tokens. Null removes a rate override. These values are configuration, not a quotation of provider pricing.
Rotation and disabling
Omitted credentials remain unchanged on PATCH. Submit a new secret to rotate it. Do not send redacted placeholder values back. Changing authentication mode must supply required new-mode fields and removes incompatible old-mode credentials.
PATCH enabled:false to disable a shared provider. Its record and app attachments remain; re-enabling restores normal availability. Shared-provider deletion is Not Generally Available. Detaching removes a reference from one app only.
Explicit connection/model tests
Saving configuration never contacts the upstream provider. Use a separate test request when you want to:
- Run a minimal configured-model check for a provider type listed in
capabilities.model_test_provider_types; it may incur usage. - Connection-only tests are Not Generally Available. A
kind:"connection"request is recognized but returnsoutcome:"unsupported"andcode:"unsupported_test_kind"for every provider.
Tests use stored credentials and endpoints; they accept no arbitrary payload, URL or credential overrides. Testing a disabled provider does not enable it. A private endpoint unreachable from the central service returns a diagnostic, not a failed configuration save.
Completed tests return test.configuration_version, kind, model, outcome, code and completed_at (Unix seconds). latency_ms is present when a supported model probe runs. Outcomes are passed, failed or unsupported. A connection test never becomes a model call. Model tests are unavailable in a deployment with COMPLETELY_NO_GPU; there are no automatic billable retries.
Provider lists support limit and cursor; filtering by enabled or provider_name is Not Generally Available. Saves and reads return { "provider": { ... }, "request_id": "..." }; ordinary responses omit upstream secrets.
Provider endpoints
/providersList shared providers
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 2
limit (query)integeroptionalcursor (query)stringoptionalNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/providers?limit=50' \
--header 'Authorization: Bearer <management-key>'
/providersCreate a shared provider
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
providers:writePath, query & header parameters 1
Idempotency-Key (header)stringrequiredFull request body specification application/json
Shared-provider configuration. Creation requires label and provider_name plus credentials for that type. Label and provider type are immutable. Saves never probe upstream.
labelstringrequiredprovider_namestringrequired"openai""azureopenai""general""quilr_ai""anthropic""anthropic_messages""anthropic_messages_bedrock""anthropic_messages_azure""deepseek""vertex_ai""gemini_chatcompletions""oracle""openai_responses""openai_responses_azure""oracle_responses""openai_assistants""openai_assistants_azure""openai_realtime""openai_realtime_azure""bedrock""bedrock_embeddings""cohere_rerank""bedrock_rerank""jina_rerank""voyage_rerank""general_rerank""sarvam"provider_settingsobjectoptionalSupply fields for the chosen provider type. Omitted PATCH credentials are preserved. Azure uses azure_api_version. Provider-specific required credentials are validated against the merged configuration.
Object fields
anthropic_versionstringoptionalOptional Anthropic API version header.
api_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
auth_typestringoptional"api_key""express""service_account""adc""gateway_user_principal""user_principal""session_principal""instance_principal""resource_principal"aws_access_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
aws_auth_modestringoptional"static""assume_role"aws_external_idstringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
aws_regionstringoptionalaws_role_arnstringoptionalaws_role_session_namestringoptionalaws_secret_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
aws_session_duration_secondsintegeroptionalaws_session_tokenstringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
azure_api_versionstringoptionalAzure API version.
azure_endpointstringoptionalbase_urlstringoptionalgcp_project_idstringoptionalgcp_regionstringoptionaloci_compartment_idstringoptionaloci_fingerprintstringoptionaloci_private_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
oci_private_key_passphrasestringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
oci_project_idstringoptionaloci_regionstringoptionaloci_session_tokenstringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
oci_tenancy_idstringoptionaloci_user_idstringoptionalservice_account_jsonstringoptionalJSON-encoded Google service account document.
Unknown fields are rejected in this object.
selected_modelsarray<string>optionalArray item specification
stringmodel_costsmap<string, object | null>optionalMap value specification
ModelCost object
input_per_1mnumber | nulloptionalUSD per million tokens; null removes this override.
Variant 1 number
numberUSD per million tokens; null removes this override.
Also accepts null.
output_per_1mnumber | nulloptionalUSD per million tokens; null removes this override.
Variant 1 number
numberUSD per million tokens; null removes this override.
Also accepts null.
cache_per_1mnumber | nulloptionalUSD per million tokens; null removes this override.
Variant 1 number
numberUSD per million tokens; null removes this override.
Also accepts null.
Unknown fields are rejected in this object.
Also accepts null.
enabledbooleanoptionalUnknown fields are rejected in this object.
curl --request POST \
'https://management.example.com/llmgateway/management/v1/providers' \
--header 'Authorization: Bearer <management-key>' \
--header 'Idempotency-Key: unique-operation-001' \
--header 'Content-Type: application/json' \
--data '{
"label": "Production OpenAI",
"provider_name": "openai",
"provider_settings": {
"api_key": "<provider-api-key>"
},
"selected_models": [
"gpt-4.1-mini"
]
}'
/providers/{label}Read a shared provider
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 1
label (path)stringrequiredNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/providers/Production%20OpenAI' \
--header 'Authorization: Bearer <management-key>'
/providers/{label}Update or disable a provider
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
providers:writePath, query & header parameters 2
label (path)stringrequiredIf-Match (header)stringrequiredQuoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.
Full request body specification application/json
Shared-provider configuration. Creation requires label and provider_name plus credentials for that type. Label and provider type are immutable. Saves never probe upstream.
labelstringoptionalprovider_namestringoptional"openai""azureopenai""general""quilr_ai""anthropic""anthropic_messages""anthropic_messages_bedrock""anthropic_messages_azure""deepseek""vertex_ai""gemini_chatcompletions""oracle""openai_responses""openai_responses_azure""oracle_responses""openai_assistants""openai_assistants_azure""openai_realtime""openai_realtime_azure""bedrock""bedrock_embeddings""cohere_rerank""bedrock_rerank""jina_rerank""voyage_rerank""general_rerank""sarvam"provider_settingsobjectoptionalSupply fields for the chosen provider type. Omitted PATCH credentials are preserved. Azure uses azure_api_version. Provider-specific required credentials are validated against the merged configuration.
Object fields
anthropic_versionstringoptionalOptional Anthropic API version header.
api_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
auth_typestringoptional"api_key""express""service_account""adc""gateway_user_principal""user_principal""session_principal""instance_principal""resource_principal"aws_access_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
aws_auth_modestringoptional"static""assume_role"aws_external_idstringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
aws_regionstringoptionalaws_role_arnstringoptionalaws_role_session_namestringoptionalaws_secret_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
aws_session_duration_secondsintegeroptionalaws_session_tokenstringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
azure_api_versionstringoptionalAzure API version.
azure_endpointstringoptionalbase_urlstringoptionalgcp_project_idstringoptionalgcp_regionstringoptionaloci_compartment_idstringoptionaloci_fingerprintstringoptionaloci_private_keystringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
oci_private_key_passphrasestringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
oci_project_idstringoptionaloci_regionstringoptionaloci_session_tokenstringoptionalWrite-only secret. Omission preserves an existing secret on PATCH. Never echo redacted placeholders.
oci_tenancy_idstringoptionaloci_user_idstringoptionalservice_account_jsonstringoptionalJSON-encoded Google service account document.
Unknown fields are rejected in this object.
selected_modelsarray<string>optionalArray item specification
stringmodel_costsmap<string, object | null>optionalMap value specification
ModelCost object
input_per_1mnumber | nulloptionalUSD per million tokens; null removes this override.
Variant 1 number
numberUSD per million tokens; null removes this override.
Also accepts null.
output_per_1mnumber | nulloptionalUSD per million tokens; null removes this override.
Variant 1 number
numberUSD per million tokens; null removes this override.
Also accepts null.
cache_per_1mnumber | nulloptionalUSD per million tokens; null removes this override.
Variant 1 number
numberUSD per million tokens; null removes this override.
Also accepts null.
Unknown fields are rejected in this object.
Also accepts null.
enabledbooleanoptionalUnknown fields are rejected in this object.
curl --request PATCH \
'https://management.example.com/llmgateway/management/v1/providers/Production%20OpenAI' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Content-Type: application/json' \
--data '{
"enabled": false
}'
/providers/{label}/testTest connection or model
Stored configuration only. Connection tests return unsupported_test_kind. Model tests are limited to model_test_provider_types from capabilities and are disabled under COMPLETELY_NO_GPU. Connection-only testing is Not Generally Available.
providers:writePath, query & header parameters 1
label (path)stringrequiredFull request body specification application/json
kindstringrequiredModel tests support the provider types advertised by capabilities. Connection-only tests are Not Generally Available and return unsupported_test_kind.
"connection""model"modelstringoptionalUnknown fields are rejected in this object.
curl --request POST \
'https://management.example.com/llmgateway/management/v1/providers/Production%20OpenAI/test' \
--header 'Authorization: Bearer <management-key>' \
--header 'Content-Type: application/json' \
--data '{
"kind": "model",
"model": "gpt-4.1-mini"
}'
Full app configuration input
Use PATCH /llmgateway/management/v1/apps/{app_name} with the current app ETag. The same settings sections are accepted during app creation. The reference below uses the implemented wire names.
Partial updates
Omitted fields preserve stored values. Unknown top-level and section fields are rejected. Nested maps such as category actions and sensitivities use the existing gateway merge semantics; an empty map is not a global reset. Lists such as tags, routing groups and custom-definition selections replace the list. [] clears a list where an empty list is supported; a provider-backed app must retain providers.
Only timeout, concurrency_per_minute, rate_limit, allowed_source_ips, jwt_auth and alerting accept a null reset at the public field level. Other fields, including token_limits, reject null. App-level timeout is a nonnegative integer in seconds.
When updating alerting, send its complete configuration, including the HTTPS URL for every submitted webhook. Omit the entire field to preserve it. Redacted webhook URLs from a read cannot be reused as credentials.
Configuration map
detection.enabled_categories maps existing built-in category IDs, or already-selected custom IDs, to booleans. Use detection.custom_definitions to select existing tenant definitions by ID; new regex/EDM/semantic/intent content is not accepted.
JWT authentication
Use access.jwt_auth with allowed_issuers, allowed_client_ids, an RSA public_key_pem, optional kid and optional enabled. Enabled configuration requires nonempty issuer/client-ID lists. Saves do not fetch JWKS URLs. null, {} or { "enabled": false } disables JWT authentication.
Settings under QuilrQL
Policy-governed changes can save and return inactive_under_quilrql, including affected fields and active_revision. Shared-provider credentials/availability, prompt contents and whole-app availability have independent runtime effects. See QuilrQL behavior, including the allowed-models default for eligible new apps.
Complete PATCH schema
AppPatchStored app settings. Omitted fields are preserved. Unknown top-level and section fields are rejected. Nested controls follow the existing gateway validators. Responses report settings that are inactive under QuilrQL.
detectionobjectoptionalObject fields
category_actionsmap<string, string>optionalCategory ID to action.
Map value specification
stringAdversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.
Values: "monitor""partial-redact""redact""block"
category_scopesmap<string, string>optionalMap value specification
stringValues: "request""response""both"
category_sensitivitiesmap<string, array<string>>optionalMap value specification
array<string>custom_definitionsarray<object>optionalFull replacement of definition selections; [] removes selections. Does not delete definitions.
Array item specification
definition_idstringrequiredStable ID from GET /custom-definitions.
enabledbooleanoptionalactionstringoptionalAdversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.
"monitor""partial-redact""redact""block"scopestringoptional"request""response""both"sensitivitystringoptional"low""medium""high"Unknown fields are rejected in this object.
data_risk_actionstringoptionalAdversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.
"monitor""partial-redact""redact""block"edm_pattern_sensitivitiesmap<string, string>optionalMap value specification
stringValues: "low""medium""high"
enabled_categoriesmap<string, boolean>optionalCatalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.
Map value specification
booleanguardian_agentobjectoptionalPartial update of Guardian branches. Set a branch enabled:false to disable it. Model-backed checks follow deployment capability.
Object fields
enabledbooleanoptionalcoding_helpersobjectoptionalObject fields
enabledbooleanoptionaldependency_security_checkbooleanoptionallatest_version_suggestionsbooleanoptionaltask_adherenceobjectoptionalObject fields
enabledbooleanoptionalactionstringoptional"nudge""block"sensitivitystringoptional"low""medium""high"agent_purposestringoptionalguardian_agent_promptstringoptionalhallucination_check_actionstringoptional"block""monitor"hallucination_check_risk_levelstringoptionalhallucination_check_score_thresholdnumberoptionalis_hallucination_check_enabledbooleanoptionalscan_encoded_imagesbooleanoptionalscan_encoded_images_scopestringoptional"request""response""both"scan_imagesbooleanoptionalscan_images_scopestringoptional"request""response""both"sub_category_actionsmap<string, map<string, string>>optionalCategory ID to subcategory name to action.
Map value specification
map<string, string>sub_category_sensitivitiesmap<string, map<string, string>>optionalMap value specification
map<string, string>Unknown fields are rejected in this object.
limitsobjectoptionalObject fields
concurrency_per_minuteinteger | nulloptionalmodel_rate_limitsarray<object>optionalArray item specification
provider_labelstringrequiredExact, trimmed tenant-wide provider label. Immutable after creation.
modelstringrequiredExact configured model identifier; availability depends on the provider and deployment.
timeoutnumber | nulloptionalSeconds.
Variant 1 number
numberSeconds.
Also accepts null.
concurrency_per_minuteinteger | nulloptionalRequest admissions per 60 seconds, following existing gateway semantics.
Variant 1 integer
integerRequest admissions per 60 seconds, following existing gateway semantics.
Also accepts null.
rate_limitobject | nulloptionalRateLimit object
valueintegerrequiredMaximum events in the window; zero disables this limit.
durationstringrequired"minute""hour""day"Also accepts null.
token_limitsobject | nulloptionalTokenLimits object
max_per_requestinteger | nulloptionalMaximum input tokens per request; zero disables.
Variant 1 integer
integerMaximum input tokens per request; zero disables.
Also accepts null.
inputobject | nulloptionalRateLimit object
valueintegerrequiredMaximum events in the window; zero disables this limit.
durationstringrequired"minute""hour""day"Also accepts null.
outputobject | nulloptionalRateLimit object
valueintegerrequiredMaximum events in the window; zero disables this limit.
durationstringrequired"minute""hour""day"Also accepts null.
Also accepts null.
rate_limitobject | nulloptionalRateLimit object
valueintegerrequiredMaximum events in the window; zero disables this limit.
durationstringrequired"minute""hour""day"Also accepts null.
rate_limit_per_minuteintegeroptionaltimeoutinteger | nulloptionaltoken_limitsobjectoptionalObject fields
max_per_requestinteger | nulloptionalMaximum input tokens per request; zero disables.
Variant 1 integer
integerMaximum input tokens per request; zero disables.
Also accepts null.
inputobject | nulloptionalRateLimit object
valueintegerrequiredMaximum events in the window; zero disables this limit.
durationstringrequired"minute""hour""day"Also accepts null.
outputobject | nulloptionalRateLimit object
valueintegerrequiredMaximum events in the window; zero disables this limit.
durationstringrequired"minute""hour""day"Also accepts null.
Unknown fields are rejected in this object.
routingobjectoptionalObject fields
custom_routingarray<object>optionalArray item specification
groupstringoptional"chat_completion""anthropic_messages""vertex_ai""responses""bedrock_runtime"typestringrequired"Low_Context_Request""Medium_Context_Request""High_Context_Request"is_publishedbooleanrequiredmodelsarray<object>requiredArray item specification
provider_namestringrequiredmodelstringrequiredlabelstringoptionalcredential_sourcestringoptionalrouting_groupsarray<object>optionalArray item specification
group_namestringrequiredgroup_kindstringoptional"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"modelsarray<object>requiredArray item specification
provider_namestringrequiredmodel_namestringrequiredcredential_sourcestringoptionalAttached shared-provider label; no inline credentials.
weightnumberrequiredrouting_thresholdsobjectoptional0 <= low_max_words <= medium_max_words.
Object fields
low_max_wordsintegerrequiredmedium_max_wordsintegerrequiredUnknown fields are rejected in this object.
token_based_routing_groupsarray<object>optionalArray item specification
group_namestringrequiredgroup_kindstringoptional"chat_completion""anthropic_messages""vertex_ai""responses""realtime""bedrock_runtime"modelsarray<object>requiredArray item specification
provider_namestringrequiredmodel_namestringrequiredcredential_sourcestringoptionalAttached shared-provider label; no inline credentials.
weightnumberrequiredUnknown fields are rejected in this object.
accessobjectoptionalObject fields
allowed_source_ipsone of 3 variantsoptionalVariant 1 array<string>
array<string>Variant 2 object
enabledbooleanoptionalipsarray<string>optionalArray item specification
stringUnknown fields are rejected in this object.
Also accepts null.
allowed_user_domainsarray<string>optionalArray item specification
stringallowed_user_emailsarray<string>optionalArray item specification
stringenforce_conversation_idbooleanoptionalenforce_identitybooleanoptionalidentity_header_modebooleanoptionalidentity_token_headersarray<string>optionalArray item specification
stringidentity_token_oid_fallbackbooleanoptionaljwt_authobject | nulloptionalJwtAuth object
enabledbooleanoptionalallowed_issuersarray<string>optionalArray item specification
stringallowed_client_idsarray<string>optionalArray item specification
stringpublic_key_pemstringoptionalRSA public key in PEM format. Required for an enabled configuration; saves do not fetch JWKS URLs.
kidstringoptionalUnknown fields are rejected in this object.
Also accepts null.
Unknown fields are rejected in this object.
transformationsobjectoptionalObject fields
token_savingobjectoptionalObject fields
smart_json_compressionbooleanoptionalhtml_to_textbooleanoptionalmarkdown_to_textbooleanoptionaltext_compressionbooleanoptionalUnknown fields are rejected in this object.
Unknown fields are rejected in this object.
self_serviceobjectoptionalObject fields
enable_self_servicebooleanoptionalself_serviceobjectoptionalStored self-service configuration. Access-control roles live inside this object. Omit to preserve; the section itself does not accept null.
Object fields
access_controlobject | nulloptionalVariant 1 object
version1optionalself_service_viewerobjectoptionalDeny rules win. A group reference never changes group membership.
Object fields
allow_allbooleanoptionalallow_emailsarray<string>optionalArray item specification
stringdeny_emailsarray<string>optionalArray item specification
stringallow_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
deny_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
settings_update_requesterobjectoptionalDeny rules win. A group reference never changes group membership.
Object fields
allow_allbooleanoptionalallow_emailsarray<string>optionalArray item specification
stringdeny_emailsarray<string>optionalArray item specification
stringallow_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
deny_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
settings_update_directobjectoptionalDeny rules win. A group reference never changes group membership.
Object fields
allow_allbooleanoptionalallow_emailsarray<string>optionalArray item specification
stringdeny_emailsarray<string>optionalArray item specification
stringallow_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
deny_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
show_api_keyobjectoptionalDeny rules win. A group reference never changes group membership.
Object fields
allow_allbooleanoptionalallow_emailsarray<string>optionalArray item specification
stringdeny_emailsarray<string>optionalArray item specification
stringallow_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
deny_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
show_logs_for_all_usersobjectoptionalDeny rules win. A group reference never changes group membership.
Object fields
allow_allbooleanoptionalallow_emailsarray<string>optionalArray item specification
stringdeny_emailsarray<string>optionalArray item specification
stringallow_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
deny_smart_groupsarray<string>optionalArray item specification
stringExisting gateway smart-group name.
Also accepts null.
Unknown fields are rejected in this object.
promptsobjectoptionalObject fields
require_system_from_storebooleanoptionalUnknown fields are rejected in this object.
enabledbooleanoptionalsmart_group_policiesarray<object>optionalArray item specification
enabled_categoriesmap<string, boolean>optionalCatalog category/subcategory IDs mapped to enabled state. Unknown selectors are rejected.
Map value specification
booleancategory_actionsmap<string, string>optionalCategory ID to action.
Map value specification
stringAdversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.
Values: "monitor""partial-redact""redact""block"
sub_category_actionsmap<string, map<string, string>>optionalCategory ID to subcategory name to action.
Map value specification
map<string, string>category_scopesmap<string, string>optionalMap value specification
stringValues: "request""response""both"
category_sensitivitiesmap<string, array<string>>optionalMap value specification
array<string>group_namestringrequiredenabledbooleanoptionalactionsobjectoptionalObject fields
data_risk_actionstringoptionalAdversarial detections do not expose redactable spans; incompatible actions are rejected by catalog validation.
"monitor""partial-redact""redact""block"hallucination_check_actionstringoptional"block""monitor"sub_category_sensitivitiesmap<string, map<string, string>>optionalMap value specification
map<string, string>Unknown fields are rejected in this object.
alertingobject | nulloptionalAlerting object
app_levelobjectoptionalObject fields
enabledbooleanoptionalwindow_minutesintegeroptionalfailure_rate_thresholdnumberoptionalPercentage.
minimum_requestsintegeroptionalcooldown_minutesintegeroptionalnotify_on_recoverybooleanoptionalprovider_levelobjectoptionalObject fields
enabledbooleanoptionalwindow_minutesintegeroptionalfailure_rate_thresholdnumberoptionalPercentage.
minimum_requestsintegeroptionalcooldown_minutesintegeroptionalnotify_on_recoverybooleanoptionalchannelsobjectoptionalObject fields
emailsarray<string>optionalArray item specification
stringwebhooksarray<object>optionalArray item specification
idstringoptionaltypestringoptional"slack""generic"labelstringoptionalurlstringrequiredHTTPS webhook URL, required for each submitted webhook. Omit the whole alerting field to preserve stored configuration.
Also accepts null.
provider_labelsarray<string>optionalArray item specification
stringtagsarray<string>optionalArray item specification
stringUnknown fields are rejected in this object.
Example: guardrails, limits and an existing group
{
"detection": {
"data_risk_action": "redact",
"enabled_categories": {"data_risk_category_pii": true},
"custom_definitions": [{
"definition_id": "employee_id",
"enabled": true,
"action": "block",
"scope": "request"
}],
"scan_images": true,
"scan_images_scope": "request"
},
"limits": {
"timeout": 60,
"rate_limit": {"value": 1000, "duration": "minute"},
"token_limits": {"max_per_request": 16000}
},
"smart_group_policies": [{
"group_name": "engineering",
"enabled": true,
"actions": {"data_risk_action": "monitor"}
}],
"transformations": {"token_saving": {"smart_json_compression": true}},
"prompts": {"require_system_from_store": true}
}
This assumes employee_id and engineering exist in the authenticated tenant. Query the catalogs first. OCR availability follows the deployment's model capability.
Example: weighted routing
{
"routing": {
"routing_groups": [{
"group_name": "support-chat",
"group_kind": "chat_completion",
"models": [
{"provider_name": "openai", "credential_source": "Production OpenAI", "model_name": "gpt-4.1-mini", "weight": 80},
{"provider_name": "openai", "credential_source": "Backup OpenAI", "model_name": "gpt-4.1-mini", "weight": 20}
]
}],
"custom_routing": [],
"routing_thresholds": {"low_max_words": 200, "medium_max_words": 1000}
}
}
Both providers must already be attached with compatible models. Weights sum to 100. routing_groups and token_based_routing_groups are separate lists; omission preserves the other list. Use shared-provider references rather than inline credentials.
Catalogs and configuration history
Read existing tenant resources and inspect configuration changes. These APIs do not expose inference traffic logs or operational reporting.
Catalogs
GET /smart-groups and GET /custom-definitions support limit and cursor; a q search filter is Not Generally Available. Individual resource reads use group_name or definition_id. Definition catalog records use the stable edm_id; pass that value as definition_id when selecting it in an app.
Existing groups/definitions can be referenced in app configuration. Group/membership writes and regex/EDM/semantic/intent authoring are Not Generally Available through these APIs.
Configuration history
List versions with /apps/{app_name}/versions; read one with /versions/{version_id}. Individual reads return version_record, with metadata and redacted previous_config/new_config snapshots when present. Unsafe legacy diffs are omitted.
Rollback requires the current app ETag and Idempotency-Key. It restores eligible settings as a new configuration change. It cannot rename the app, alter credential expiry, mutate provider/definition resources, restore inline credentials, change JWT keys or restore internal-only settings. Routing/group references are revalidated. App rollback does not roll back policy revisions.
Audit
GET /audit returns tenant management events with event_id, actor, operation, resource, request_id, result, created_at and changes. created_at uses Unix seconds. Only limit and cursor are supported; app-name, operation, management-key and time-range filters are Not Generally Available.
Operation recovery
After 503 operation_pending, retain error.operation_id. Read /operations/{operation_id} with read using the same key that initiated the operation. The response contains operation_id, state, created_at and request_id.
POST /operations/{operation_id}/recover with config:write retries a saved configuration write and audit. It refuses to overwrite a later different configuration. An already completed operation returns its ID/state; a recovered configuration can also include app and warnings.
App/provider/credential creation recovers by retrying the original POST and Idempotency-Key, not the recovery endpoint. Read the retry contract before automating recovery.
/apps/{app_name}/versionsList app configuration versions
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 3
app_name (path)stringrequiredlimit (query)integeroptionalcursor (query)stringoptionalNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/versions?limit=50' \
--header 'Authorization: Bearer <management-key>'
/apps/{app_name}/versions/{version_id}Read a configuration version
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 2
app_name (path)stringrequiredversion_id (path)stringrequiredNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/versions/version_example' \
--header 'Authorization: Bearer <management-key>'
/apps/{app_name}/versions/{version_id}/rollbackRoll back app configuration
Restricted app configuration rollback; no policy rollback. Requires the current app ETag and Idempotency-Key.
config:writePath, query & header parameters 4
app_name (path)stringrequiredversion_id (path)stringrequiredIf-Match (header)stringrequiredQuoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.
Idempotency-Key (header)stringrequiredFull request body specification application/json
Unknown fields are rejected in this object.
curl --request POST \
'https://management.example.com/llmgateway/management/v1/apps/Support%20Bot/versions/version_example/rollback' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Idempotency-Key: unique-operation-001' \
--header 'Content-Type: application/json' \
--data '{}'
/smart-groupsList smart groups
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 2
limit (query)integeroptionalcursor (query)stringoptionalNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/smart-groups?limit=50' \
--header 'Authorization: Bearer <management-key>'
/smart-groups/{group_name}Read a smart group
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 1
group_name (path)stringrequiredNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/smart-groups/engineering' \
--header 'Authorization: Bearer <management-key>'
/custom-definitionsList custom definitions
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 2
limit (query)integeroptionalcursor (query)stringoptionalNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/custom-definitions?limit=50' \
--header 'Authorization: Bearer <management-key>'
/custom-definitions/{definition_id}Read a custom definition
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below.
readPath, query & header parameters 1
definition_id (path)stringrequiredNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/custom-definitions/employee_id' \
--header 'Authorization: Bearer <management-key>'
/auditGet audit
Tenant management events, including actor, resource, result and created_at in Unix seconds. Only limit/cursor are supported; no app/key/time filters.
readPath, query & header parameters 2
limit (query)integeroptionalcursor (query)stringoptionalNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/audit?limit=50' \
--header 'Authorization: Bearer <management-key>'
/operations/{operation_id}Get operation
Status is visible only to the same management key that initiated the operation.
readPath, query & header parameters 1
operation_id (path)stringrequiredNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/operations/operation_example' \
--header 'Authorization: Bearer <management-key>'
/operations/{operation_id}/recoverPost recover
Retry a saved configuration write using the initiating key. Requires config:write. Creation must instead retry the original POST with its original Idempotency-Key.
config:writePath, query & header parameters 1
operation_id (path)stringrequiredFull request body specification application/json
Unknown fields are rejected in this object.
curl --request POST \
'https://management.example.com/llmgateway/management/v1/operations/operation_example/recover' \
--header 'Authorization: Bearer <management-key>' \
--header 'Content-Type: application/json' \
--data '{}'
/app/versionsList app configuration versions (query locator)
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.
readPath, query & header parameters 3
app_name (query)stringrequiredExact display name; encode with standard query URL encoding.
limit (query)integeroptionalcursor (query)stringoptionalNo request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/app/versions?app_name=Support%20Bot&limit=50' \
--header 'Authorization: Bearer <management-key>'
/app/versions/{version_id}Read a configuration version (query locator)
Tenant-scoped operation. Resource reads return redacted metadata; writes use the permissions and preconditions shown below. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.
readPath, query & header parameters 2
version_id (path)stringrequiredapp_name (query)stringrequiredExact display name; encode with standard query URL encoding.
No request body.
curl --request GET \
'https://management.example.com/llmgateway/management/v1/app/versions/version_example?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>'
/app/versions/{version_id}/rollbackRoll back app configuration (query locator)
Restricted app configuration rollback; no policy rollback. Requires the current app ETag and Idempotency-Key. Use app_name in the query for names containing slashes or literal percent signs; URL-encode the query value once.
config:writePath, query & header parameters 4
version_id (path)stringrequiredapp_name (query)stringrequiredExact display name; encode with standard query URL encoding.
If-Match (header)stringrequiredQuoted ETag returned by the latest resource read. Prompt/attachment/rollback writes use the app ETag.
Idempotency-Key (header)stringrequiredFull request body specification application/json
Unknown fields are rejected in this object.
curl --request POST \
'https://management.example.com/llmgateway/management/v1/app/versions/version_example/rollback?app_name=Support%20Bot' \
--header 'Authorization: Bearer <management-key>' \
--header 'If-Match: "resource-version-from-read"' \
--header 'Idempotency-Key: unique-operation-001' \
--header 'Content-Type: application/json' \
--data '{}'