Skip to main content
POST
Error
This endpoint is available in Bifrost Enterprise only.
Required Permissions How permissions work

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint.

OSS setup lock. On Bifrost OSS, while dashboard auth is not active (no admin account, or auth disabled), every management endpoint except the public ones (/health, /api/version, /api/session/is-auth-enabled, /api/session/login, ...) requires the operator's setup token in the X-Bifrost-Setup-Token header, in place of Authorization. The token is set with setup_token in config.json or the BIFROST_SETUP_TOKEN environment variable. A missing header returns 401, a wrong token 403. The header stops working once dashboard auth is enabled. The dashboard instead trades the token once for an HttpOnly bifrost_setup_session cookie via POST /api/session/setup. See Required permissions for how permissions are derived and which endpoints are exempt.

Body

application/json
name
string
required
Maximum string length: 255
description
string
tags
string[]
provider_configs
object[]
budgets
object[]
rate_limit
object
calendar_aligned
boolean
allow_all_providers
boolean
default:false

When true, grants access to every provider, including ones without a provider_configs entry and providers added later. A listed provider keeps its own model allow/blacklist, budgets, rate limits, and key selection; an unlisted provider gets all models, all keys, and no per-provider limits. When false (default), access is deny-by-default via provider_configs.

auto_rotation_interval

Schedule automatic rotation of the profile's managed virtual keys. Accepts a day count ("30d"), a Go duration ("12h"), or integer nanoseconds. Between 1h and 365d; omit, "" or 0 to leave it off.

Pattern: ^$|^[0-9]+d$|^([0-9]+(\.[0-9]+)?(ns|us|µs|ms|s|m|h))+$
Example:

"30d"

next_rotation_at
string<date-time>

Optional first rotation time; must be in the future and requires auto_rotation_interval. Defaults to now + interval.

virtual_mcps
object[]

A Virtual MCP granted to the profile. Assignments are a set, so a repeat collapses rather than doubling.

mcp_configs
object[]
mcp_tool_groups
object[]
deprecated

DEPRECATED: use virtual_mcps.

mcp_servers
object[]
deprecated

DEPRECATED: use mcp_configs. Folded in on save.

mcp_tool_overrides
object[]
deprecated

DEPRECATED: use mcp_configs. Folded in on save.

Response

Profile created

access_profile
object