- Org enforced shared key - when the organization has a key configured
and
policy="enforced". - User’s org-scoped personal key - when the caller has saved a key against the current organization.
- User’s pure-personal key - the caller’s account-wide key.
- None - the session prompts for a key (or fails if the agent does not support prompting).
- The resolved endpoints for Anthropic and OpenAI, which return what the resolution above would produce without exposing the actual key value.
- The generic provider key endpoints used for the additional agents (Cursor, Devin, Gemini, Copilot), which support the same personal/org + resolution model.
All endpoints on this page only return masked previews and metadata -
values are never returned.
Anthropic resolved key
GET /api/user/anthropic-key/resolved
Required scope:
integrations:readHeaders
string
required
Bearer <your_api_key>string
Optional. Includes org-shared and user-scoped-org keys in the resolution.
Response
boolean
true when a key would be available; false when the session would
prompt.string
Where the resolved key came from. One of
"org" (enforced shared key),
"user_org" (caller’s key for this org), "user" (caller’s pure-personal
key), or "none" when has_key is false.string
Masked preview of the resolved key, or
null.OpenAI resolved key
GET /api/user/openai-key/resolved
Required scope:
integrations:readHeaders
string
required
Bearer <your_api_key>string
Optional.
Response
Same shape as/api/user/anthropic-key/resolved.
Generic provider keys
For agents other than Anthropic and OpenAI, the API exposes a single set of endpoints parameterised byprovider. The supported providers are:
The personal/org behavior, policy semantics, and
enforced requirements
match the Anthropic and OpenAI endpoints on the dedicated pages.
Values are never returned. Responses include only a masked preview, a
connected / has_key flag, and the active policy (for org keys).GET /api/user/provider-keys/
Required scope:
integrations:readPath Parameters
string
required
One of
cursor, devin, gemini, copilot.Headers
string
required
Bearer <your_api_key>string
Optional.
Response
string
Echo of the path
provider.boolean
true if the caller has a personal key for this provider.string
Masked preview, or
null.string
ISO 8601 timestamp of the last update, or
null.PUT /api/user/provider-keys/
Required scope:
integrations:writePath Parameters
string
required
One of
cursor, devin, gemini, copilot.Request Body
string
required
Provider API key (minimum 8 characters). Treated as opaque text.
Response
Same shape asGET, with connected: true.
DELETE /api/user/provider-keys/
Required scope:
integrations:writePath Parameters
string
required
One of
cursor, devin, gemini, copilot.Response
Same shape asGET, with connected: false.
GET /api/user/provider-keys//resolved
Required scope:
integrations:readPath Parameters
string
required
One of
cursor, devin, gemini, copilot.Response
string
Echo of the path
provider.boolean
true when a key would be available; false when the session would
prompt.string
Where the resolved key came from. One of
"org", "user_org", "user",
or "none".string
Masked preview of the resolved key, or
null.Organization provider keys
Organization context is required. Set
X-Organization-Id to match the
path org_id, or use an org-scoped API key whose org ID matches.GET /api/organizations//provider-keys/
Required scope:
integrations:readPath Parameters
string
required
Organization ID. Must match
X-Organization-Id (or the API key’s org).string
required
One of
cursor, devin, gemini, copilot.Response
string
Echo of the path
org_id.string
Echo of the path
provider.boolean
true when the org has a stored key for this provider.string
Masked preview, or
null.string
"individual" (default) or "enforced".string
ISO 8601 timestamp of the last update, or
null.PUT /api/organizations//provider-keys/
Required scope:
integrations:writepolicy="enforced" requires the org to have a stored key (either supplied in
the same call or already present).
Path Parameters
string
required
Organization ID.
string
required
One of
cursor, devin, gemini, copilot.Request Body
string
Provider API key (minimum 8 characters when provided). Required when
switching to
policy="enforced" for the first time.string
"individual" (default) or "enforced".Response
Same shape as the GET response, reflecting the updated state.DELETE /api/organizations//provider-keys/
Required scope:
integrations:write"individual".
Path Parameters
string
required
Organization ID.
string
required
One of
cursor, devin, gemini, copilot.Response
Same shape as the GET response, withhas_key: false, key_preview: null,
and policy: "individual".