A valid request URL is required to generate request examples{
"message": "<string>",
"plugin": {
"name": "my_custom_plugin",
"actualName": "MyCustomPlugin",
"enabled": true,
"config": {
"api_key": "xxx"
},
"isCustom": true,
"path": "/plugins/my_custom_plugin.so",
"status": {
"name": "my_custom_plugin",
"status": "active",
"logs": [
"plugin my_custom_plugin initialized successfully"
],
"types": [
"llm",
"http"
]
}
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}Create a new plugin
Creates a new plugin with the specified configuration.
Setting path on a non-builtin plugin loads native code (a .so, via dlopen) into the
gateway process and requires genuine admin authentication - it is refused with 403 if
dashboard authentication is disabled or unconfigured, even though other management
endpoints remain reachable in that state. Only http/https URLs are fetched for
remote paths, and by default only ones resolving to a public address; private,
loopback, link-local, and CGNAT addresses are additionally allowed if explicitly
listed in the deploy-time server.plugin_download_private_allowlist config. Local
filesystem paths are unaffected.
A valid request URL is required to generate request examples{
"message": "<string>",
"plugin": {
"name": "my_custom_plugin",
"actualName": "MyCustomPlugin",
"enabled": true,
"config": {
"api_key": "xxx"
},
"isCustom": true,
"path": "/plugins/my_custom_plugin.so",
"status": {
"name": "my_custom_plugin",
"status": "active",
"logs": [
"plugin my_custom_plugin initialized successfully"
],
"types": [
"llm",
"http"
]
}
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}| Permission | Granted via |
|---|---|
Plugins:Create | RBAC role or API key scope |
Authorizations
Management API authentication for /api/* endpoints. Use the Authorization header
with Bearer <token>, where <token> is one of:
- a Bifrost management API key,
- a dashboard session token issued by
POST /api/session/login, - base64 of
<admin-username>:<admin-password>(legacy equivalent ofBasicAuth).
Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs -
the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.
Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a
Required Permissions table (Resource:Operation, for example Dashboard:View) above
its Authorizations section, and the caller's RBAC role or management API key scopes must
include what it lists, otherwise the request is rejected with 403 Forbidden.
A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.
Response
Plugin created successfully
Plugin operation response
Plugin configuration
Show child attributes
Show child attributes
{
"name": "my_custom_plugin",
"actualName": "MyCustomPlugin",
"enabled": true,
"config": { "api_key": "xxx" },
"isCustom": true,
"path": "/plugins/my_custom_plugin.so",
"status": {
"name": "my_custom_plugin",
"status": "active",
"logs": [
"plugin my_custom_plugin initialized successfully"
],
"types": ["llm", "http"]
}
}
Was this page helpful?

