Skip to main content
POST
Error
Required Permissions How permissions work

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.

Body

application/json

Create virtual key request

name
string
required
description
string
provider_configs
object[]

Provider configurations. When allow_all_providers is omitted or false, an empty list allows no providers (deny-by-default); when true, providers without a config are allowed with all models and keys.

mcp_configs
object[]

MCP configurations (empty means no MCP tools allowed, deny-by-default)

team_id
string
customer_id
string
budgets
object[]

Budget quotas assigned directly to this virtual key. Use this array instead of the removed singular budget or budget_id fields.

rate_limit
object

Create rate limit request

is_active
boolean
calendar_aligned
boolean
default:false
allow_all_providers
boolean
default:false

When true, this virtual key may use every configured provider. provider_configs remain optional per-provider overrides for budgets, rate limits, model allow/blacklists, and key selection.

expires_at
string<date-time>

Optional expiry timestamp. Must be in the future. Omit for a key that never expires.

Response

Virtual key created successfully

Virtual key operation response

message
string
required
virtual_key
object
required

Virtual key configuration