import * as z from "zod/v4"; import { Result as SafeParseResult } from "../types/fp.js"; import { BYOKProviderSlug } from "./byokproviderslug.js"; import { SDKValidationError } from "./errors/sdkvalidationerror.js"; export type BYOKKey = { /** * Optional allowlist of OpenRouter API key hashes (`api_keys.hash`) that may use this credential. `null` means no restriction. */ allowedApiKeyHashes: Array | null; /** * Optional allowlist of model slugs this credential may be used for. `null` means no restriction. */ allowedModels: Array | null; /** * Optional allowlist of user IDs that may use this credential. `null` means no restriction. */ allowedUserIds: Array | null; /** * ISO timestamp of when the credential was created. */ createdAt: string; /** * Your declaration of whether the upstream provider account behind this credential has zero data retention (ZDR). `null` inherits OpenRouter's data policy for the provider's endpoint; `true` declares the account ZDR so requests that require ZDR may route to this credential even when the shared endpoint retains data; `false` declares it non-ZDR so such requests never route to it. Self-declared and not verified by OpenRouter. */ declaredZdr: boolean | null; /** * Whether this credential is currently disabled. */ disabled: boolean; /** * Stable public identifier for this BYOK credential. */ id: string; /** * Whether OpenRouter's shared endpoints on this provider are removed for every model, including models outside `allowed_models` and after all of your keys for the provider fail. The provider is skipped instead of spending OpenRouter credits. Only valid on non-fallback credentials. */ isByokOnly: boolean; /** * Whether this credential is treated as a fallback — used only after non-fallback keys for the same provider have been tried. Cannot be combined with `is_byok_only`. */ isFallback: boolean; /** * Whether OpenRouter's shared endpoints on this provider are removed for the models this credential applies to (its `allowed_models`, or every model when `null`). Requests for those models run only on your keys; models outside the allowlist may still fall back to shared capacity on this provider. */ isRequired: boolean; /** * Short masked snippet of the key (e.g. the first/last few characters) used to identify it in the UI. */ label: string; /** * Optional human-readable name for the credential. */ name?: string | null | undefined; /** * The upstream provider this credential authenticates against, as a lowercase slug (e.g. `openai`, `anthropic`, `amazon-bedrock`). */ provider: BYOKProviderSlug; /** * Position within the provider — credentials are tried in ascending sort order. */ sortOrder: number; /** * The workspace this credential is scoped to, or `null` when it is global — usable across every workspace in the account. A `null` value does not mean the default workspace. */ workspaceId: string | null; }; /** @internal */ export declare const BYOKKey$inboundSchema: z.ZodType; export declare function byokKeyFromJSON(jsonString: string): SafeParseResult; //# sourceMappingURL=byokkey.d.ts.map