Skip to main content
GET
Error
Required Permissions How permissions work

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.

Response

Successful response

Global proxy configuration

enabled
boolean
type
enum<string>
Available options:
http,
socks5,
tcp
url
string

Proxy URL (http or https). Private and loopback hosts are accepted; link-local and unspecified addresses are rejected.

username
string
password
string

Password (redacted as in responses)

no_proxy
string
timeout
integer
skip_tls_verify
boolean
enable_for_scim
boolean
enable_for_inference
boolean
enable_for_api
boolean