--- title: "BYOKKey" --- ## Fields | Field | Type | Required | Description | Example | | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | | `allowed_api_key_hashes` | List[*str*] | :heavy_check_mark: | Optional allowlist of OpenRouter API key hashes (`api_keys.hash`) that may use this credential. `null` means no restriction. | [
"f01d52606dc8f0a8303a7b5cc3fa07109c2e346cec7c0a16b40de462992ce943"
] | | `allowed_models` | List[*str*] | :heavy_check_mark: | Optional allowlist of model slugs this credential may be used for. `null` means no restriction. | null | | `allowed_user_ids` | List[*str*] | :heavy_check_mark: | Optional allowlist of user IDs that may use this credential. `null` means no restriction. | null | | `created_at` | *str* | :heavy_check_mark: | ISO timestamp of when the credential was created. | 2025-08-24T10:30:00Z | | `disabled` | *bool* | :heavy_check_mark: | Whether this credential is currently disabled. | false | | `id` | *str* | :heavy_check_mark: | Stable public identifier for this BYOK credential. | 11111111-2222-3333-4444-555555555555 | | `is_fallback` | *bool* | :heavy_check_mark: | Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried. | false | | `label` | *str* | :heavy_check_mark: | Short masked snippet of the key (e.g. the first/last few characters) used to identify it in the UI. | sk-...AbCd | | `name` | *OptionalNullable[str]* | :heavy_minus_sign: | Optional human-readable name for the credential. | Production OpenAI Key | | `provider` | [components.BYOKProviderSlug](../components/byokproviderslug.mdx) | :heavy_check_mark: | The upstream provider this credential authenticates against, as a lowercase slug (e.g. `openai`, `anthropic`, `amazon-bedrock`). | openai | | `sort_order` | *int* | :heavy_check_mark: | Position within the provider — credentials are tried in ascending sort order. | 0 | | `workspace_id` | *str* | :heavy_check_mark: | ID of the workspace this credential belongs to. | 550e8400-e29b-41d4-a716-446655440000 |