Files
openrouter-python-sdk-retry…/docs/sdks/oauth
OpenRouter Team 1cad51abb6 Commits included in this export:
- 6ddaaa6989d725bbe966e45f7aed0c1bd72f9153
  - 4779741b6ba710b1299612b82e8544516bd9dd6a
  - 22083fcc8f58884d8212d6f3314b231c4ddd21cd
  - a925a620f97196d509e073a163caac053bd82316
  - 5c05d8829784601ffd151acef1a6978c266f913d
  - 6f4fff535fbf4274255c255ae23620b8e00e614f
  - ef358e96cb01e469b77d44683603a602b0813116
  - e6299b4ebfe5c2eed6c598771f0fd99f84555401
  - 24d3f0ee1c2aa19a62f7902836034080b9246813
  - 68922847c2969b773887310eb7aa9a814e199c5a
  - 729ee2338c39df22461526153e7f4ba868fd498e
  - e1074ff86fccf5e48406b7595298873106d3cc5a
  - 123bbdaf841d299162a82ee2573adfbb70a45b8f
  - ac457b8a8dad98fdf5ddcae8dd4711361cea3084
  - ea825199f4c59dd68fec01cf8d18a582963c9f25
  - 4d48e4f6bb936e785787314a965298da6b78fea0
  - 718729a573ee98893a4408d5a52ab4686661fe54
  - b867adcde6b64f3f2a11c4626254b39098e4b0b4
  - 21912c097b4066d109766c6b4492826595cd57c5
  - bc1ed85adc976a4634ca8a41b82e4fc2c39a864f
  - d145c89c941937a312ed1357590d2bfda9a3603d
  - 12f05b5dee397ead47cfcd545a7a2e3c7ff57524
  - dd28f75a19a015809797c7abf3f8758f7c37262e
  - c96e569781e07ab44172d9c69940ec17bafd81f4
  - c9d5a90e3c2b5077a2bdd49773f1a46d1a5a79c7
  - 58b08f87116ceab9076de2fdc0a4c74c919b44c4

GitOrigin-RevId: 6ddaaa6989d725bbe966e45f7aed0c1bd72f9153
2026-02-05 23:15:21 +00:00
..
2026-02-05 23:15:21 +00:00

OAuth

(o_auth)

Overview

OAuth authentication endpoints

Available Operations

exchange_auth_code_for_api_key

Exchange an authorization code from the PKCE flow for a user-controlled API key

Example Usage

from openrouter import OpenRouter
import os


with OpenRouter(
    http_referer="<value>",
    x_title="<value>",
    api_key=os.getenv("OPENROUTER_API_KEY", ""),
) as open_router:

    res = open_router.o_auth.exchange_auth_code_for_api_key(code="auth_code_abc123def456")

    # Handle response
    print(res)

Parameters

Parameter Type Required Description Example
code str ✔️ The authorization code received from the OAuth redirect auth_code_abc123def456
http_referer Optional[str] The app identifier should be your app's URL and is used as the primary identifier for rankings.
This is used to track API usage per application.
x_title Optional[str] The app display name allows you to customize how your app appears in OpenRouter's dashboard.
code_verifier Optional[str] The code verifier if code_challenge was used in the authorization request dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk
code_challenge_method OptionalNullable[operations.ExchangeAuthCodeForAPIKeyCodeChallengeMethod] The method used to generate the code challenge S256
retries Optional[utils.RetryConfig] Configuration to override the default retry behavior of the client.

Response

operations.ExchangeAuthCodeForAPIKeyResponse

Errors

Error Type Status Code Content Type
errors.BadRequestResponseError 400 application/json
errors.ForbiddenResponseError 403 application/json
errors.InternalServerResponseError 500 application/json
errors.OpenRouterDefaultError 4XX, 5XX */*

create_auth_code

Create an authorization code for the PKCE flow to generate a user-controlled API key

Example Usage

from openrouter import OpenRouter
import os


with OpenRouter(
    http_referer="<value>",
    x_title="<value>",
    api_key=os.getenv("OPENROUTER_API_KEY", ""),
) as open_router:

    res = open_router.o_auth.create_auth_code(callback_url="https://myapp.com/auth/callback")

    # Handle response
    print(res)

Parameters

Parameter Type Required Description Example
callback_url str ✔️ The callback URL to redirect to after authorization. Note, only https URLs on ports 443 and 3000 are allowed. https://myapp.com/auth/callback
http_referer Optional[str] The app identifier should be your app's URL and is used as the primary identifier for rankings.
This is used to track API usage per application.
x_title Optional[str] The app display name allows you to customize how your app appears in OpenRouter's dashboard.
code_challenge Optional[str] PKCE code challenge for enhanced security E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
code_challenge_method Optional[operations.CreateAuthKeysCodeCodeChallengeMethod] The method used to generate the code challenge S256
limit Optional[float] Credit limit for the API key to be created 100
expires_at date Optional expiration time for the API key to be created
retries Optional[utils.RetryConfig] Configuration to override the default retry behavior of the client.

Response

operations.CreateAuthKeysCodeResponse

Errors

Error Type Status Code Content Type
errors.BadRequestResponseError 400 application/json
errors.UnauthorizedResponseError 401 application/json
errors.InternalServerResponseError 500 application/json
errors.OpenRouterDefaultError 4XX, 5XX */*