Skip to main content
PUT
Upsert Provider Credential

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

Idempotency-Key
string

Unique key for idempotent requests. If provided, the server ensures the request is processed at most once. Retries with the same key return the original response. SDKs auto-generate this for write requests.

Example:

"550e8400-e29b-41d4-a716-446655440000"

Path Parameters

slot
enum<string>
required
Available options:
anthropic,
openai,
google,
aws_bedrock

Body

application/json

Credential material for one slot. Which fields are required depends on the slot.

api_key
string | null

API key for the anthropic/openai slots, or the Bedrock API key when bedrock_auth_mode=api_key.

service_account_json
string | null

Google Cloud service account key file contents (JSON string) for the google slot.

bedrock_auth_mode
enum<string> | null

AWS Bedrock authentication mode: 'api_key' (Bedrock API key) or 'iam' (access key pair).

Available options:
api_key,
iam
aws_access_key_id
string | null
aws_secret_access_key
string | null
aws_region
string | null

AWS region for Bedrock. One of: us-east-1, us-east-2, us-west-2.

Response

Successful Response

State of one BYOK slot. Never includes secret material.

slot
enum<string>
required
Available options:
anthropic,
openai,
google,
aws_bedrock
display_name
string
required
source
enum<string>
required

'cyberdesk' when the slot has never been configured (Cyberdesk platform keys are used).

Available options:
cyberdesk,
organization
covered_providers
string[]
required
status
enum<string> | null
Available options:
active,
invalid,
missing
auth_type
enum<string> | null
Available options:
api_key,
service_account_json,
aws_bedrock_api_key,
aws_iam
display_metadata
ProviderCredentialDisplayMetadata · object

Non-secret metadata shown in the dashboard.

last_error
string | null
activated_at
string<date-time> | null
last_validated_at
string<date-time> | null
created_at
string<date-time> | null
updated_at
string<date-time> | null