Skip to main content
PUT
Error
Required Permissions How permissions work

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.

Path Parameters

provider
string
required

Provider name

Body

application/json

Update provider request. Keys are managed separately via /api/providers/{provider}/keys.

network_config
object

Network configuration for provider connections

concurrency_and_buffer_size
object

Concurrency settings

proxy_config
object

Proxy configuration

send_back_raw_request
boolean
send_back_raw_response
boolean
store_raw_request_response
boolean
custom_provider_config
object

Custom provider configuration

prompt_cache
object

Synthesize prompt-cache breakpoints for requests that carry none. Off by default. Requests that already carry their own cache markers are never modified.

Response

Provider updated successfully

Provider configuration response

name
enum<string>

AI model provider identifier

Available options:
anthropic,
azure,
bedrock,
bedrock_mantle,
cerebras,
cohere,
deepseek,
gemini,
groq,
mistral,
ollama,
opencode-go,
opencode-zen,
openai,
parasail,
perplexity,
sgl,
vertex,
openrouter,
elevenlabs,
huggingface,
nebius,
xai,
replicate,
vllm,
runway,
runware,
fireworks,
sarvam,
wafer,
databricks
network_config
object

Network configuration for provider connections

concurrency_and_buffer_size
object

Concurrency settings

proxy_config
object

Proxy configuration

send_back_raw_request
boolean
send_back_raw_response
boolean
store_raw_request_response
boolean
custom_provider_config
object

Custom provider configuration

prompt_cache
object

Synthesize prompt-cache breakpoints for requests that carry none. Off by default. Requests that already carry their own cache markers are never modified.

provider_status
enum<string>

Status of the provider

Available options:
active,
error,
deleted
status
string

Operational status (e.g., list_models_failed)

description
string

Error/status description

config_hash
string

Hash of config.json version, used for change detection