Skip to main content
When a session boots, Runtime picks the right credential for the chosen agent in this order:
  1. Org enforced shared key - when the organization has a key configured and policy="enforced".
  2. User’s org-scoped personal key - when the caller has saved a key against the current organization.
  3. User’s pure-personal key - the caller’s account-wide key.
  4. None - the session prompts for a key (or fails if the agent does not support prompting).
This page covers two surfaces:
  • The resolved endpoints for Anthropic and OpenAI, which return what the resolution above would produce without exposing the actual key value.
  • The generic provider key endpoints used for the additional agents (Cursor, Devin, Gemini, Copilot), which support the same personal/org + resolution model.
All endpoints on this page only return masked previews and metadata - values are never returned.

Anthropic resolved key

GET /api/user/anthropic-key/resolved

Required scope: integrations:read
Returns the Anthropic key that would be used to start a session right now, without exposing the key value.

Headers

string
required
Bearer <your_api_key>
string
Optional. Includes org-shared and user-scoped-org keys in the resolution.

Response

boolean
true when a key would be available; false when the session would prompt.
string
Where the resolved key came from. One of "org" (enforced shared key), "user_org" (caller’s key for this org), "user" (caller’s pure-personal key), or "none" when has_key is false.
string
Masked preview of the resolved key, or null.

OpenAI resolved key

GET /api/user/openai-key/resolved

Required scope: integrations:read
Identical resolution behavior to the Anthropic endpoint, returning the OpenAI key that would be used to start a Codex (or other OpenAI-backed) session right now.

Headers

string
required
Bearer <your_api_key>
string
Optional.

Response

Same shape as /api/user/anthropic-key/resolved.

Generic provider keys

For agents other than Anthropic and OpenAI, the API exposes a single set of endpoints parameterised by provider. The supported providers are: The personal/org behavior, policy semantics, and enforced requirements match the Anthropic and OpenAI endpoints on the dedicated pages.
Values are never returned. Responses include only a masked preview, a connected / has_key flag, and the active policy (for org keys).

GET /api/user/provider-keys/

Required scope: integrations:read
Read the caller’s stored personal provider key for the current context.

Path Parameters

string
required
One of cursor, devin, gemini, copilot.

Headers

string
required
Bearer <your_api_key>
string
Optional.

Response

string
Echo of the path provider.
boolean
true if the caller has a personal key for this provider.
string
Masked preview, or null.
string
ISO 8601 timestamp of the last update, or null.

PUT /api/user/provider-keys/

Required scope: integrations:write
Save a personal provider key.

Path Parameters

string
required
One of cursor, devin, gemini, copilot.

Request Body

string
required
Provider API key (minimum 8 characters). Treated as opaque text.

Response

Same shape as GET, with connected: true.

DELETE /api/user/provider-keys/

Required scope: integrations:write
Remove the caller’s stored personal provider key for the current context.

Path Parameters

string
required
One of cursor, devin, gemini, copilot.

Response

Same shape as GET, with connected: false.

GET /api/user/provider-keys//resolved

Required scope: integrations:read
Inspect which provider key would be used at session creation time. Same resolution semantics as the Anthropic and OpenAI resolved endpoints above.

Path Parameters

string
required
One of cursor, devin, gemini, copilot.

Response

string
Echo of the path provider.
boolean
true when a key would be available; false when the session would prompt.
string
Where the resolved key came from. One of "org", "user_org", "user", or "none".
string
Masked preview of the resolved key, or null.

Organization provider keys

Setting and deleting an organization provider key requires the caller to be an org owner or admin.
Organization context is required. Set X-Organization-Id to match the path org_id, or use an org-scoped API key whose org ID matches.

GET /api/organizations//provider-keys/

Required scope: integrations:read
Read the org’s stored provider key (status only) and the active policy.
Path Parameters
string
required
Organization ID. Must match X-Organization-Id (or the API key’s org).
string
required
One of cursor, devin, gemini, copilot.
Response
string
Echo of the path org_id.
string
Echo of the path provider.
boolean
true when the org has a stored key for this provider.
string
Masked preview, or null.
string
"individual" (default) or "enforced".
string
ISO 8601 timestamp of the last update, or null.

PUT /api/organizations//provider-keys/

Required scope: integrations:write
Org owner or admin role required.
Set the org provider key, the active policy, or both. Setting policy="enforced" requires the org to have a stored key (either supplied in the same call or already present).
Path Parameters
string
required
Organization ID.
string
required
One of cursor, devin, gemini, copilot.
Request Body
string
Provider API key (minimum 8 characters when provided). Required when switching to policy="enforced" for the first time.
string
"individual" (default) or "enforced".
Response
Same shape as the GET response, reflecting the updated state.

DELETE /api/organizations//provider-keys/

Required scope: integrations:write
Org owner or admin role required.
Remove the org provider key and reset the policy to "individual".
Path Parameters
string
required
Organization ID.
string
required
One of cursor, devin, gemini, copilot.
Response
Same shape as the GET response, with has_key: false, key_preview: null, and policy: "individual".