> ## Documentation Index
> Fetch the complete documentation index at: https://bifrost-backport-semantic-cache-scope.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Creating API Keys

> Create and use API keys to call Bifrost management API endpoints.

## Overview

Bifrost management API endpoints are the endpoints that interact directly with Bifrost itself, instead of sending inference requests to model providers. These include APIs for RBAC, governance, users, teams, virtual keys, providers, plugins, logs, configuration, and similar control-plane operations.

Use an API key as the bearer token when calling these endpoints from scripts, backend services, CI jobs, or other automation.

## Create An API Key

1. Open the Bifrost dashboard.
2. Go to **Settings** > **API Keys**.
3. Click **Create API Key**.
4. Give the key a recognizable name. Assign the scopes based on the permissions you would like to give the key.
5. Create the key.
6. Copy the generated key and store it in your secret manager.

Keys can also be managed over the API itself — see [Create an API key](/api-reference/api-keys/create-an-api-key). A key's access comes from its scopes alone and never inherits the creator's role, and you can only grant scopes you already hold yourself.

<Warning>
  Copy the generated key when it is shown and follow general security practices.
</Warning>

## Required Permissions

Every management endpoint in the [API reference](/api-reference) shows a **Required Permissions** table above its Authorizations section, listing each permission as `Resource:Operation` (for example `Dashboard:View`). You do not need to work it out from the URL: open the endpoint page and grant exactly what the table lists.

One permission catalog backs both ways of calling the management API:

| Caller | Where the permission must be granted |
| - | - |
| Dashboard user or SSO session | The user's [RBAC role](/enterprise/rbac) must include the permission. |
| Management API key | The key's **scopes** must include the permission. Select the scopes that match the endpoints the key will call when you create it. |

A request whose role or key lacks the permission is rejected with `403 Forbidden`.

### How a permission is derived

* **Resource** is taken from the URL. It is usually the first segment after `/api/` (`/api/webhooks/...` requires `Webhooks`), but several paths map to a different resource. For example, `/api/logs/stats`, `/api/logs/histogram/*`, and `/api/logs/rankings*` require `Dashboard`, not `Logs`, and `/api/governance/audit-logs*` requires `AuditLogs`, not `Governance`.
* **Operation** defaults to the HTTP method: `GET` requires `View`, `POST` requires `Create`, `PUT` and `PATCH` require `Update`, and `DELETE` requires `Delete`. A few endpoints override this, for example `POST /api/logs/recalculate-cost` requires `Logs:Update` and `POST /api/license` requires `Settings:Update`.

Because these rules have exceptions, always rely on the **Required Permissions** table on the endpoint page rather than the URL.

### Endpoints that list no permission

* **Public** endpoints (for example `GET /health`, `GET /api/version`, `POST /api/session/login`) require no authentication.
* **Exempt** endpoints (for example `GET /api/config`, `POST /api/session/ws-ticket`, `GET /api/governance/users/me/permissions`) require authentication but skip the permission check, so any authenticated management caller can use them.
* **Not RBAC-gated** endpoints authenticate with the credential itself rather than a role or scope, such as `GET /api/governance/virtual-keys/quota`, which accepts only a virtual key.

<Info>
  Permissions and API key scopes are enforced in **Bifrost Enterprise**. Open-source Bifrost has no per-endpoint permissions: any caller that passes management authentication (the admin password or a dashboard session) can use every management endpoint.
</Info>

<Note>
  A local admin who signs in with the admin password bypasses RBAC entirely. Separately, [Data Access Control](/enterprise/data-access-control) can narrow *which rows* a permitted caller sees, for example the logs behind `/api/logs/stats`, without changing the permission the endpoint requires.
</Note>

## Management API Endpoints

Use this bearer token for management API endpoints that configure or inspect Bifrost. The following endpoint patterns use management API authentication in the OpenAPI spec.

<Info>The `/api/routing/*` routes are available in **Bifrost v2.0.0 and above**. On earlier versions the routing endpoints live under `/api/governance/*`.</Info>

Governance resources moved under the `/api/governance` namespace. Both generations are listed: the canonical route is the one to build against, and the rows marked *deprecated aliases* are the pre-move paths, which still answer today and are scheduled for removal in the following major release. See the [v2.0.0 migration guide](/migration-guides/v2.0.0#breaking-change-3-governance-apis-moved-to-the-api-governance-namespace) for the full mapping.

| Area | Endpoint patterns |
| - | - |
| Configuration | `/api/config`, `/api/proxy-config`, `/api/pricing/force-sync` |
| Providers and models | `/api/providers`, `/api/providers/{provider}`, `/api/providers/{provider}/keys`, `/api/providers/{provider}/keys/{key_id}`, `/api/keys`, `/api/models`, `/api/models/base`, `/api/models/details`, `/api/models/parameters` |
| Plugins | `/api/plugins`, `/api/plugins/builtins`, `/api/plugins/{name}` |
| Routing | `/api/routing/rules`, `/api/routing/rules/{rule_id}`, `/api/routing/complexity-analyzer-config`, `/api/routing/complexity-analyzer-config/reset` |
| Routing (deprecated aliases) | `/api/governance/routing-rules`, `/api/governance/routing-rules/{rule_id}`, `/api/governance/complexity-analyzer-config`, `/api/governance/complexity-analyzer-config/reset` (the paths these endpoints shipped under). Still served and still covered by the same scope as the canonical paths above, so an existing key keeps working; new integrations should use `/api/routing`. |
| Governance | `/api/governance/virtual-keys`, `/api/governance/virtual-keys/{vk_id}`, `/api/governance/teams`, `/api/governance/teams/{team_id}`, `/api/governance/customers`, `/api/governance/customers/{customer_id}`, `/api/governance/budgets`, `/api/governance/rate-limits`, `/api/governance/model-configs`, `/api/governance/model-configs/{mc_id}`, `/api/governance/providers`, `/api/governance/providers/{provider_name}`, `/api/governance/pricing-overrides`, `/api/governance/pricing-overrides/{id}` |
| Business units | `/api/governance/business-units`, `/api/governance/business-units/{business_unit_id}`, `/api/governance/business-units/{business_unit_id}/teams`, `/api/governance/business-units/{business_unit_id}/teams/{team_id}`, `/api/governance/business-units/{business_unit_id}/customers`, `/api/governance/business-units/{business_unit_id}/customers/{customer_id}`, `/api/governance/business-units/{business_unit_id}/governance`, `/api/governance/customers/{customer_id}/business-units` |
| RBAC | `/api/governance/rbac/roles`, `/api/governance/rbac/roles/{role_id}`, `/api/governance/rbac/roles/{role_id}/permissions`, `/api/governance/rbac/resources`, `/api/governance/rbac/operations`, `/api/governance/rbac/permissions` |
| RBAC (deprecated aliases) | `/api/roles`, `/api/roles/{role_id}`, `/api/roles/{role_id}/permissions`, `/api/resources`, `/api/operations`, `/api/permissions` |
| Users and teams | `/api/governance/users`, `/api/governance/users/{user_id}`, `/api/governance/users/{user_id}/role`, `/api/governance/users/{user_id}/teams`, `/api/governance/users/me/permissions`, `/api/governance/users/email/{email}`, `/api/governance/users/email/{email}/virtual-keys`, `/api/governance/users/{user_id}/virtual-keys`, `/api/governance/teams`, `/api/governance/teams/{team_id}`, `/api/governance/teams/{team_id}/members`, `/api/governance/teams/{team_id}/members/{user_id}` |
| Users and teams (deprecated aliases) | `/api/users`, `/api/users/{user_id}`, `/api/users/{user_id}/role`, `/api/users/{user_id}/teams`, `/api/users/me/permissions`, `/api/users/email/{email}`, `/api/users/email/{email}/virtual-keys`, `/api/users/{user_id}/virtual-keys`, `/api/teams`, `/api/teams/{team_id}`, `/api/teams/{team_id}/members`, `/api/teams/{team_id}/members/{user_id}` |
| Access profiles | `/api/governance/access-profiles`, `/api/governance/access-profiles/{profile_id}`, `/api/governance/access-profiles/{profile_id}/activate`, `/api/governance/access-profiles/{profile_id}/deactivate`, `/api/governance/access-profiles/{profile_id}/clone`, `/api/governance/access-profiles/{profile_id}/propagate`, `/api/governance/access-profiles/{profile_id}/roles`, `/api/governance/access-profiles/{profile_id}/roles/{role_id}`, `/api/governance/access-profiles/{profile_id}/versions`, `/api/governance/access-profiles/{profile_id}/versions/{version}`, `/api/governance/access-profiles/{profile_id}/audit-logs`, `/api/governance/access-profiles/audit-logs`, `/api/governance/users/{user_id}/access-profiles`, `/api/governance/users/{user_id}/access-profiles/{profile_id}`, `/api/governance/users/{user_id}/access-profiles/{profile_id}/virtual-keys`, `/api/governance/users/{user_id}/access-profiles/virtual-keys/{vk_id}`, `/api/governance/users/{user_id}/access-profiles/{profile_id}/budgets/{budget_id}/override` |
| Access profiles (deprecated aliases) | `/api/access-profiles`, `/api/access-profiles/{profile_id}`, `/api/access-profiles/{profile_id}/activate`, `/api/access-profiles/{profile_id}/deactivate`, `/api/access-profiles/{profile_id}/clone`, `/api/access-profiles/{profile_id}/propagate`, `/api/access-profiles/{profile_id}/roles`, `/api/access-profiles/{profile_id}/roles/{role_id}`, `/api/access-profiles/{profile_id}/versions`, `/api/access-profiles/{profile_id}/versions/{version}`, `/api/access-profiles/{profile_id}/audit-logs`, `/api/access-profiles/audit-logs`, `/api/users/{user_id}/access-profiles`, `/api/users/{user_id}/access-profiles/{profile_id}`, `/api/users/{user_id}/access-profiles/{profile_id}/virtual-keys`, `/api/users/{user_id}/access-profiles/virtual-keys/{vk_id}`, `/api/users/{user_id}/access-profiles/{profile_id}/budgets/{budget_id}/override` |
| Logs and analytics | `/api/logs`, `/api/logs/{id}`, `/api/logs/sessions/{session_id}`, `/api/logs/sessions/{session_id}/summary`, `/api/logs/stats`, `/api/logs/filterdata`, `/api/logs/dashboard`, `/api/logs/dropped`, `/api/logs/rankings`, `/api/logs/recalculate-cost`, `/api/logs/recalculate-cost/status`, `/api/logs/histogram`, `/api/logs/histogram/cost`, `/api/logs/histogram/tokens`, `/api/logs/histogram/models`, `/api/logs/histogram/latency`, `/api/logs/histogram/cost/by-provider`, `/api/logs/histogram/tokens/by-provider`, `/api/logs/histogram/latency/by-provider`, `/api/logs/histogram/cost/by-dimension`, `/api/logs/histogram/tokens/by-dimension`, `/api/logs/histogram/latency/by-dimension` |
| MCP logs | `/api/mcp-logs`, `/api/mcp-logs/{id}`, `/api/mcp-logs/stats`, `/api/mcp-logs/filterdata`, `/api/mcp-logs/histogram`, `/api/mcp-logs/histogram/cost`, `/api/mcp-logs/histogram/top-tools` |
| MCP clients and sessions | `/api/mcp/clients`, `/api/mcp/client`, `/api/mcp/client/{id}`, `/api/mcp/client/{id}/reconnect`, `/api/mcp/client/{id}/complete-oauth`, `/api/mcp/sessions`, `/api/mcp/sessions/{id}`, `/api/mcp/sessions/{id}/reauth`, `/api/mcp/per-user-headers/flows/{id}`, `/api/mcp/per-user-headers/credential/{id}` |
| Virtual MCPs | `/api/mcp/virtual-mcps`, `/api/mcp/virtual-mcps/{id}`, `/api/mcp/virtual-mcps/{id}/virtual-keys/{vkId}` (deprecated alias: `/api/mcp/tool-groups`, `/api/mcp/tool-groups/{id}`) |
| OAuth management | `/api/oauth/config/{id}`, `/api/oauth/config/{id}/status`, `/api/oauth/per-user/flows/{id}`, `/api/oauth/per-user/flows/{id}/start` |
| Prompt repository | `/api/prompt-repo/folders`, `/api/prompt-repo/folders/{id}`, `/api/prompt-repo/prompts`, `/api/prompt-repo/prompts/{id}`, `/api/prompt-repo/prompts/{id}/versions`, `/api/prompt-repo/versions/{id}`, `/api/prompt-repo/prompts/{id}/sessions`, `/api/prompt-repo/sessions/{id}`, `/api/prompt-repo/sessions/{id}/rename`, `/api/prompt-repo/sessions/{id}/commit` |
| Skills | `/api/skills`, `/api/skills/{id}`, `/api/skills/{id}/versions`, `/api/skills/{id}/shift-version`, `/api/skills/all/version`, `/api/skills/files/upload`, `/api/skills/files/orphans` |
| Cache | `/api/cache/clear/{cacheId}`, `/api/cache/clear-by-key/{cacheKey}` |
| Circuit breaker | `/api/circuit-breaker/policies`, `/api/circuit-breaker/policies/{name}`, `/api/circuit-breaker/state` |
| Audit logs | `/api/governance/audit-logs`, `/api/governance/audit-logs/{id}`, `/api/governance/audit-logs/filterdata`, `/api/governance/audit-logs/export`, `/api/governance/audit-logs/{id}/verify` |
| Audit logs (deprecated aliases) | `/api/audit-logs`, `/api/audit-logs/{id}`, `/api/audit-logs/filterdata`, `/api/audit-logs/export`, `/api/audit-logs/{id}/verify` |
| Webhooks | `/api/webhooks`, `/api/webhooks/{id}`, `/api/webhooks/{id}/deliveries`, `/api/webhooks/{id}/rotate-secret`, `/api/webhooks/{id}/test`, `/api/webhooks/deliveries/{id}/redeliver` |
| API keys | `/api/api-keys`, `/api/api-keys/{id}` |
| Session and vault operations | `/api/session/logout`, `/api/session/ws-ticket`, `/api/vault/flush-cache` |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.