diff --git a/.speakeasy/gen.lock b/.speakeasy/gen.lock index c17f0ae1..0432e4ff 100644 --- a/.speakeasy/gen.lock +++ b/.speakeasy/gen.lock @@ -1,19 +1,19 @@ lockVersion: 2.0.0 id: c48cf606-fb42-4a45-9c23-8f0555307828 management: - docChecksum: c3356957a0e3b86ce6da12f3d1aa1fc1 + docChecksum: 7e944d58dceb766b5a0de16f03810538 docVersion: 1.0.0 speakeasyVersion: 1.787.0 generationVersion: 2.914.0 - releaseVersion: 1.3.0 - configChecksum: 9d5f5553d383e15f2a7df8ac2f5a3746 + releaseVersion: 1.3.1 + configChecksum: e97c566d120d474c3640ed6e9a0d4c49 repoURL: https://github.com/OpenRouterTeam/python-sdk.git installationURL: https://github.com/OpenRouterTeam/python-sdk.git published: true persistentEdits: - generation_id: cd12ab81-ee6c-4d46-be7c-60749e9ea3fe - pristine_commit_hash: ac9548ca76361592e90c1f0399d4bcf1fbf23d27 - pristine_tree_hash: 477aeaf0e041f94a12af985906c7654957bef9f4 + generation_id: dc537827-c52f-4965-ab88-b176ba87b595 + pristine_commit_hash: 977a46a9ef7eb44a1a05f8f3d7a6b350d3a196e3 + pristine_tree_hash: 6b4c89128f7f0ab0947a228d7e643e68f68b8783 features: python: acceptHeaders: 3.0.0 @@ -6274,10 +6274,6 @@ trackedFiles: id: 1fdb0adb6332 last_write_checksum: sha1:ce8e66b50b882d83464fef01336e9227a514a5cb pristine_git_object: a319422a67656f477b27f3ed48149e53c6fd8405 - docs/components/scope.mdx: - id: 25b03f56752e - last_write_checksum: sha1:604855944477d8965aa373bbba3c15fa77a8b70d - pristine_git_object: ca4b238ce6dbfdbdfc9c93c11d9232c83ca14018 docs/components/searchcontextsizeenum.mdx: id: b6b9a99acb5f last_write_checksum: sha1:177016c42a56a7a8dcd40caa7e9105ca7a6ea1cc @@ -6760,8 +6756,12 @@ trackedFiles: pristine_git_object: 834297f4c2167ee22b57bd3cfb126b37662cd1ae docs/components/tokenexchangerequest.mdx: id: c1564eb38361 - last_write_checksum: sha1:e91d2e5d15beff1038a83015adf13f3feb075819 - pristine_git_object: 84a147af188137886dab4d40ff7c64cd1cec822f + last_write_checksum: sha1:c4e87426647f3cd5568160bc18a5adac444ecf65 + pristine_git_object: a086ed56570a2ace2826884497fc3fe0d2fe2337 + docs/components/tokenexchangerequestscope.mdx: + id: 786235cab16a + last_write_checksum: sha1:a436470eca241bc1e8127b80110e0a89cc8ff1d7 + pristine_git_object: 32b57f584bd0540db2465e8ef74e00528518b3e0 docs/components/tokenexchangeresponse.mdx: id: 5b7eb37933eb last_write_checksum: sha1:a0fb15d00227686dfe83a567178d71d3a7c7c710 @@ -7230,6 +7230,18 @@ trackedFiles: id: 3312b9777716 last_write_checksum: sha1:6ba9bb63173376b0dcb7ac22b859bfef3e3820eb pristine_git_object: cd3d46d3af459e7b95090a8e74e22eed448b3fdd + docs/components/vaulteffectivesecret.mdx: + id: 17fcc6025eb6 + last_write_checksum: sha1:d5b6c9e08d41719bd988e2a8814567781a69da88 + pristine_git_object: 54d681fca7dbc69fca2e22dbe05795bff5cdc432 + docs/components/vaulteffectivesecretlistresponse.mdx: + id: 061d2e48f23a + last_write_checksum: sha1:602810471f72dba1f79efc8ded2275a017c47890 + pristine_git_object: 84fe50a0bf5d10efc8a928122aed9b5680818e08 + docs/components/vaulteffectivesecretscope.mdx: + id: 63e345a2fbb5 + last_write_checksum: sha1:f8f18b91cefe607947edd77d9c40ab88c3e541a0 + pristine_git_object: 49bbc389c25f6c2b6f1cffbd0948f637a6712c4d docs/components/vaultsecret.mdx: id: f83900f9f59b last_write_checksum: sha1:9098b56d682969f3eb8fdf1b2a02174cc69ae75b @@ -8710,6 +8722,14 @@ trackedFiles: id: e829f52a26d3 last_write_checksum: sha1:cb8b441a4e0138861a6cf660367f674093844590 pristine_git_object: 590e46d83ce8a470b44499464e1343584fc66805 + docs/operations/listinterneffectivevaultsecretsglobals.mdx: + id: 3c05df20a610 + last_write_checksum: sha1:62ac9fadca5e196f129ff6f110b6b00aaba03021 + pristine_git_object: bd5c8c46493910949d648056efb4e2d301d08c4a + docs/operations/listinterneffectivevaultsecretsrequest.mdx: + id: 28d54bbf7bd0 + last_write_checksum: sha1:437819461388cce3d350fdadcec4870766d913e0 + pristine_git_object: ca1e31d1cb7936ff8e8f25da69e051cd74743b12 docs/operations/listinternsglobals.mdx: id: 6a0fb4e1a618 last_write_checksum: sha1:b257bc2c67a98c98cebc8bb1046b170d8a6757bb @@ -9364,16 +9384,16 @@ trackedFiles: pristine_git_object: 08c687694efbecf50406ae7929029d39fb121295 docs/sdks/interns/README.mdx: id: 2f8a053ffe78 - last_write_checksum: sha1:e7bbdc193de66e0a79a6a1be3f75897fd6ade785 - pristine_git_object: 9b2e94a1efa1ab6d1f80082f61d25bdb9f01d43f + last_write_checksum: sha1:756054e3c8016bf0e6297544fbc0e997820108f7 + pristine_git_object: 93cafb95428d42245c9ebdee0e464cc3487a777d docs/sdks/models/README.mdx: id: 58f1ca464e0b last_write_checksum: sha1:093dd30ebdd18b9763a6956915e0dcae4ae7d5e5 pristine_git_object: 9131aee97e483384b6721a32936c05901dfeea5d docs/sdks/oauth/README.mdx: id: 42b5079343d2 - last_write_checksum: sha1:e58bac6bbe1c443462510a1dc5dca91bb4996525 - pristine_git_object: 5e90344f13d6f49aa9399a4fd6bc2b870b54d348 + last_write_checksum: sha1:57c8bf432795162dae43b5ec3d37004ff0df0dd5 + pristine_git_object: ac1d96c8536a9f18194690db64cefa9858de2998 docs/sdks/observability/README.mdx: id: 75811527e651 last_write_checksum: sha1:c834e9881bbbf35e230ebb5dc34e6635b68fb830 @@ -9420,8 +9440,8 @@ trackedFiles: pristine_git_object: 2d7b6d76d80b07c4720ff5984742b9ca5b097f1c docs/sdks/vault/README.mdx: id: 3738c6722acd - last_write_checksum: sha1:2b26b8c7e7c88dc4aee023f518b7d8e94f1649f9 - pristine_git_object: 224e03abadbea39a7fa64d5d4733b9b5f80fefab + last_write_checksum: sha1:12acdfed4c2a32488d98b6091fd8c392af516494 + pristine_git_object: 8d9386c0a3101f823f7509e8d6d1ebb97c8339d0 docs/sdks/videogeneration/README.mdx: id: 9a8fa04c3872 last_write_checksum: sha1:6b4cbab4adb8e8573c7f01f77760bb8e0abaaa6f @@ -9436,8 +9456,8 @@ trackedFiles: pristine_git_object: 3e38f1a929f7d6b1d6de74604aa87e3d8f010544 pyproject.toml: id: 5d07e7d72637 - last_write_checksum: sha1:97b2b26c97c162638c417d551f5d0d43a6552362 - pristine_git_object: 9a4c2d4a4a872d83521c96df8d5ca708d125df6c + last_write_checksum: sha1:5059bb383c2e5a8f4529c1fcd474627aaf4f5b83 + pristine_git_object: 2abc2e9eb9f9620c40b9b8002147f9e73e91f71f scripts/prepare_readme.py: id: e0c5957a6035 last_write_checksum: sha1:77f44b60b98bc126557ec27391f91dfba764bb54 @@ -9464,8 +9484,8 @@ trackedFiles: pristine_git_object: 86713cfea633e09d33b3d4e65281071fe20e6137 src/openrouter/_version.py: id: d8d15ad6c586 - last_write_checksum: sha1:0ea1d6150dcbb51486224c29c1cd38333a00ae7f - pristine_git_object: c76512db319d82b3b6cebe4018d70281b8b105bf + last_write_checksum: sha1:c7e97a6fb6852c4f8ea4dfc6e98d2b912a6ded78 + pristine_git_object: ebd042a882653d04969096e6600ac771b0a4a066 src/openrouter/alpha.py: id: 306c4d93308d last_write_checksum: sha1:30f55a360f41376ab194b9ea725fe4e001a5ae1a @@ -9512,8 +9532,8 @@ trackedFiles: pristine_git_object: ad3d247954547814054c01989a2dff3d12b3e4e1 src/openrouter/components/__init__.py: id: 81754e97b3f4 - last_write_checksum: sha1:5b875fd512ef570b68331f22b0dd89ce57c13d60 - pristine_git_object: 0ee454721b11eefb36836850db65456c8d692464 + last_write_checksum: sha1:66cb742b924019f5a71034b5f35c82417460032a + pristine_git_object: 5c3c0093a18643a99523be50e960a0d0dddbd754 src/openrouter/components/aabenchmarkentry.py: id: e2e0f0b48c82 last_write_checksum: sha1:fab4d9a24d2cea937bb749d46c5f83941e99d65c @@ -12392,8 +12412,8 @@ trackedFiles: pristine_git_object: ffae73647f1060eeb9f46a4d331de6b9760dc5d9 src/openrouter/components/tokenexchangerequest.py: id: 2359476f8b4b - last_write_checksum: sha1:c93ebac5a861d46802866df990dd9bffd7c2a8dc - pristine_git_object: a29bf1760577ba7958a3f98bf0a95c27fbd18592 + last_write_checksum: sha1:945320dc39299eb722890d3ac2d8352e033c561a + pristine_git_object: 10c0f8aa34133562638d4421a70b007a5dbe6f13 src/openrouter/components/tokenexchangeresponse.py: id: c7c8ecb676b8 last_write_checksum: sha1:bd1d4f0bbb4c320e630e28f92504f040c927eabf @@ -12542,6 +12562,14 @@ trackedFiles: id: 5d2f6ca184f7 last_write_checksum: sha1:c638d9e565e13e3ac2e2e5630aec9e4a4487d303 pristine_git_object: 13f895170a7160c3f03f365c1c10e4bc3e1c7092 + src/openrouter/components/vaulteffectivesecret.py: + id: 7cfe3bb9003a + last_write_checksum: sha1:71298b7ec53f9fa5767972003711efb7d3bbfeee + pristine_git_object: 370c71dc11b4c609f0fe09287ddb552db0f3c784 + src/openrouter/components/vaulteffectivesecretlistresponse.py: + id: e9b4e1264f6a + last_write_checksum: sha1:fb108955818e818bea2b82871e17d2b06a361139 + pristine_git_object: 1624be980edfb263c22de91409540fb1592f75ca src/openrouter/components/vaultsecret.py: id: 9fcf1780b21c last_write_checksum: sha1:8b04cf06d4dac935e5e4d6a7fe690167a6a56ca6 @@ -12848,8 +12876,8 @@ trackedFiles: pristine_git_object: 50643a126668498dd668c7cceb9f78c03d413d32 src/openrouter/interns.py: id: d18df05c5c6d - last_write_checksum: sha1:0047c1e5a89ca5b44b26ce2a735658de2beac333 - pristine_git_object: dfcd3255b87bb272ef8fbc4bfcf23197af3b28c8 + last_write_checksum: sha1:9d720df76dd6cb9656f2b5d35f32500906927a71 + pristine_git_object: 186fde866ebf6bd323a3368d0925bf9453979782 src/openrouter/models/__init__.py: id: ed73b93abb3f last_write_checksum: sha1:932a790ae66ccd7d7022b39c659bcf72a664ebea @@ -12868,16 +12896,16 @@ trackedFiles: pristine_git_object: e16291f980d3a1e19aeef0f68cf5b4998da16f82 src/openrouter/oauth.py: id: 1948ce27255b - last_write_checksum: sha1:7e9fc1853f0c0a8116436bc9b850e848a661ecf8 - pristine_git_object: 67a8110158546a5f1ea311e63ef8d5fc1837f70b + last_write_checksum: sha1:3a64f1522bcd0680e4371e8eb2ec88122987bf61 + pristine_git_object: 6f3d587f5a6c2635328cb27a4d869b81cfbc2213 src/openrouter/observability.py: id: 6a17f32d3f33 last_write_checksum: sha1:5ce75ba2b1beb3f44ff94ef9d2dee0e59debc0ba pristine_git_object: 8680343bbc90107ae6413bd5686012b1fd75d665 src/openrouter/operations/__init__.py: id: 9afcea1e7161 - last_write_checksum: sha1:05a46c28a7f4c12a206f33662458835835a4e1af - pristine_git_object: 7f5a4f0e09cb5f8ee82cdcb5ef0559f4e222cc71 + last_write_checksum: sha1:9c8d909d254649414cbc38ac980ce571f4522fa7 + pristine_git_object: 021994be6f7184f84b27c360adb3c056d4107d0e src/openrouter/operations/activateprivateendpoint.py: id: 3b39eec5d66f last_write_checksum: sha1:9406e6b3d38c82895fd795f637702ef579cc6d36 @@ -13266,6 +13294,10 @@ trackedFiles: id: ad2131e4aa6c last_write_checksum: sha1:b5bbcbd02ce54cdc8bb1a2a3a424ca93c73f90bc pristine_git_object: 01655ae02036acf433ec5f54fd1d9323a55f0684 + src/openrouter/operations/listinterneffectivevaultsecrets.py: + id: 32772b285bb4 + last_write_checksum: sha1:d2e172f972cc8ed89dfe1541e2c4bf5314ab7490 + pristine_git_object: aa75b78b26ac046e05df9b89f265e4caf897ac91 src/openrouter/operations/listinterns.py: id: 89bc4fa38c9f last_write_checksum: sha1:8b938ac53c5ff37cc670b49c605fd7cf513be8be @@ -13572,8 +13604,8 @@ trackedFiles: pristine_git_object: dae01a44384ac3bc13ae07453a053bf6c898ebe3 src/openrouter/vault.py: id: 0645fe426ac1 - last_write_checksum: sha1:c6cd8d2dab531fc98053bcae2eb1285b0659eb28 - pristine_git_object: d73bcc0f564ebee39fdd727f9d588859abd19167 + last_write_checksum: sha1:3a0daca68628b484130fcfec530820c6dcbde67c + pristine_git_object: 7619f073a18d91f4230f51f2a1915598ef4d8a48 src/openrouter/video_generation.py: id: d0a90c1b8efe last_write_checksum: sha1:3cac67a39145deab8f1dbc8cde496bf4757d0fe0 @@ -17162,16 +17194,178 @@ examples: application/json: {"error": {"code": 500, "message": "Internal Server Error"}} "502": application/json: {"error": {"code": 502, "message": "Provider returned error"}} + listInternEffectiveVaultSecrets: + speakeasy-default-list-intern-effective-vault-secrets: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "200": + application/json: {"data": [{"created_at": "2026-09-15T17:44:00.000Z", "fingerprint": "sha256:9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08", "hosts": ["api.github.com"], "name": "github_token", "scope": "intern"}, {"created_at": "2026-09-15T17:44:00.000Z", "fingerprint": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb", "hosts": ["api.linear.app"], "name": "linear_api_key", "scope": "workspace"}, {"created_at": "2026-08-01T09:30:00.000Z", "fingerprint": null, "hosts": null, "name": "legacy_token", "scope": "workspace"}], "has_more": false} + "400": + application/json: {"error": {"code": 400, "message": "Invalid request parameters"}} + "401": + application/json: {"error": {"code": 401, "message": "Missing Authentication header"}} + "403": + application/json: {"error": {"code": 403, "message": "Only management keys can perform this operation"}} + "404": + application/json: {"error": {"code": 404, "message": "Resource not found"}} + "408": + application/json: {"error": {"code": 408, "message": "Operation timed out. Please try again later."}} + "429": + application/json: {"error": {"code": 429, "message": "Rate limit exceeded"}} + "500": + application/json: {"error": {"code": 500, "message": "Internal Server Error"}} + "502": + application/json: {"error": {"code": 502, "message": "Provider returned error"}} + "503": + application/json: {"error": {"code": 503, "message": "Service temporarily unavailable"}} + "504": + application/json: {"error": {"code": 504, "message": "The operation was aborted due to timeout"}} + invalid-vault-request: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "400": + application/json: {"error": {"code": 400, "message": "Invalid vault request"}} + invalid-or-missing-api-key: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "401": + application/json: {"error": {"code": 401, "message": "Invalid or missing API key"}} + regional-hostname: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "403": + application/json: {"error": {"code": 403, "message": "The Intern API does not support regional data residency yet. Please use the global endpoint at openrouter.ai."}} + workspace-scope-unavailable: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "403": + application/json: {"error": {"code": 403, "message": "Vault scope is unavailable"}} + not-found: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "404": + application/json: {"error": {"code": 404, "message": "Not found"}} + body-timed-out: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "408": + application/json: {"error": {"code": 408, "message": "Request body timed out"}} + route-deadline: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "408": + application/json: {"error": {"code": 408, "message": "Vault request timed out"}} + rate-limited: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "429": + application/json: {"error": {"code": 429, "message": "Too many vault requests"}} + internal-error: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "500": + application/json: {"error": {"code": 500, "message": "Internal Server Error"}} + invalid-vault-response: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "502": + application/json: {"error": {"code": 502, "message": "Invalid vault response"}} + vault-request-failed: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "502": + application/json: {"error": {"code": 502, "message": "Vault request failed"}} + vault-unavailable: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "503": + application/json: {"error": {"code": 503, "message": "Vault service is unavailable"}} + writes-disabled: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "503": + application/json: {"error": {"code": 503, "message": "Vault writes are not enabled"}} + vault-timed-out: + parameters: + path: + internId: "7c9e6679-7425-40de-944b-e07fc1f90ae7" + query: + limit: 50 + offset: 0 + responses: + "504": + application/json: {"error": {"code": 504, "message": "Vault request timed out"}} examplesVersion: 1.0.2 releaseNotes: | ## Python SDK Changes: - * `open_router.private_endpoints.list()`: **Added** - * `open_router.private_endpoints.create()`: **Added** - * `open_router.private_endpoints.delete()`: **Added** - * `open_router.private_endpoints.get()`: **Added** - * `open_router.private_endpoints.update()`: **Added** - * `open_router.private_endpoints.activate()`: **Added** - * `open_router.private_endpoints.disable()`: **Added** - * `open_router.private_endpoints.enable()`: **Added** - * `open_router.private_endpoints.update_pricing()`: **Added** - * `open_router.private_endpoints.validate()`: **Added** + * `open_router.vault.list_intern_effective_vault_secrets()`: **Added** diff --git a/.speakeasy/gen.yaml b/.speakeasy/gen.yaml index eb101e15..823b07e7 100644 --- a/.speakeasy/gen.yaml +++ b/.speakeasy/gen.yaml @@ -36,7 +36,7 @@ generation: documentation: mintlify preApplyUnionDiscriminators: true python: - version: 1.3.0 + version: 1.3.1 additionalDependencies: dev: {} main: {} diff --git a/.speakeasy/out.openapi.yaml b/.speakeasy/out.openapi.yaml index cf7da4d7..bbd41194 100644 --- a/.speakeasy/out.openapi.yaml +++ b/.speakeasy/out.openapi.yaml @@ -30756,6 +30756,90 @@ components: required: - 'workspace_id' type: 'object' + VaultEffectiveSecret: + additionalProperties: false + description: 'Metadata for the one secret the intern''s outbound requests receive under this name. The secret value is never returned. The intern receives it only on requests to a hostname in `hosts`, or on any request when `hosts` is `null`; a request to any other hostname receives no secret under this name, even when another vault holds one. `fingerprint` is comparable only within one vault.' + example: + created_at: '2026-09-15T17:44:00.000Z' + fingerprint: 'sha256:9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08' + hosts: + - 'api.github.com' + name: 'github_token' + scope: 'intern' + properties: + created_at: + format: 'date-time' + type: 'string' + fingerprint: + pattern: '^sha256:[a-f0-9]{64}$' + type: + - 'string' + - 'null' + hosts: + items: + maxLength: 254 + type: 'string' + maxItems: 100 + minItems: 1 + type: + - 'array' + - 'null' + name: + maxLength: 255 + minLength: 1 + pattern: '^(?!.*__)[a-z]([a-z0-9_]*[a-z0-9])?$' + type: 'string' + scope: + description: 'Where the delivered secret is stored: `intern` for the intern''s own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault.' + enum: + - 'intern' + - 'attached' + - 'workspace' + type: 'string' + x-speakeasy-unknown-values: allow + required: + - 'name' + - 'hosts' + - 'fingerprint' + - 'created_at' + - 'scope' + type: 'object' + VaultEffectiveSecretListResponse: + additionalProperties: false + description: 'One page of the secrets an intern receives, one entry per name.' + example: + data: + - created_at: '2026-09-15T17:44:00.000Z' + fingerprint: 'sha256:9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08' + hosts: + - 'api.github.com' + name: 'github_token' + scope: 'intern' + - created_at: '2026-09-15T17:44:00.000Z' + fingerprint: 'sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb' + hosts: + - 'api.linear.app' + name: 'linear_api_key' + scope: 'workspace' + - created_at: '2026-08-01T09:30:00.000Z' + fingerprint: null + hosts: null + name: 'legacy_token' + scope: 'workspace' + has_more: false + properties: + data: + items: + $ref: '#/components/schemas/VaultEffectiveSecret' + maxItems: 100 + type: 'array' + has_more: + description: 'True when more secrets exist beyond this page. Request the next page with `offset` increased by the number of returned entries.' + type: 'boolean' + required: + - 'data' + - 'has_more' + type: 'object' VaultSecret: additionalProperties: false description: 'Metadata for one stored secret. The secret value is never returned. `fingerprint` is an HMAC-SHA-256 of the value keyed with that vault''s own data key, so it is comparable only within one vault: equal fingerprints in one vault mean equal values, and rewriting the same value keeps its fingerprint. The same value stored in two vaults (for example a workspace secret and its intern copy) carries different fingerprints, so comparing fingerprints across vaults cannot show that a copy matches or that a rotation propagated. `hosts` and `fingerprint` are `null` only for legacy rows written before host binding was required; storing the secret again assigns hosts.' @@ -39295,7 +39379,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /interns: get: - description: 'Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'listInterns' parameters: - description: 'Maximum number of interns to return, from 1 through 500.' @@ -39452,7 +39536,7 @@ paths: tags: - 'Interns' post: - description: 'Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'createIntern' parameters: - description: 'Key that makes retries resume the same create operation, from 1 through 255 characters. An empty or longer key is refused with 400. Without the header, the server derives a stable key from the request body.' @@ -39666,7 +39750,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /interns/{internId}: delete: - description: 'Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{"acknowledge_workspace_loss": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{"acknowledge_workspace_loss": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'deleteIntern' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -39825,7 +39909,7 @@ paths: tags: - 'Interns' get: - description: 'Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'getIntern' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -39924,7 +40008,7 @@ paths: tags: - 'Interns' patch: - description: 'Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'updateIntern' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -40333,7 +40417,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /interns/{internId}/daemon: get: - description: 'Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'getInternDaemon' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -40436,7 +40520,7 @@ paths: /interns/{internId}/daemon-access: get: deprecated: true - description: 'Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'getInternDaemonAccess' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -40749,7 +40833,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /interns/{internId}/provision: post: - description: 'Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'provisionIntern' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -40905,7 +40989,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /interns/{internId}/suspend: post: - description: 'Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern''s own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'suspendIntern' parameters: - description: 'ID of an intern visible to the authenticated API key.' @@ -48302,9 +48386,236 @@ paths: - $ref: "#/components/parameters/AppIdentifier" - $ref: "#/components/parameters/AppDisplayName" - $ref: "#/components/parameters/AppCategories" + /vault/interns/{internId}/effective-secrets: + get: + description: 'Lists, one entry per name, the secret the intern''s outbound requests receive: its own secrets, secrets from an attached vault, and workspace secrets, including ones stored before workspace-scoped storage. Where several vaults hold a name, the entry is the one that wins, in the order intern, attached, workspace. The same resolution decides what outbound requests receive, so this list and the intern''s requests agree. `scope` says which vault the entry comes from. Responses carry metadata only, never values. Results are ordered by name and paginated with `limit` and `offset`. Returns 404 when the intern''s attached vault is no longer available, since the intern then receives no secrets. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + operationId: 'listInternEffectiveVaultSecrets' + parameters: + - description: 'UUID of an intern in the workspace selected by the API key.' + in: 'path' + name: 'internId' + required: true + schema: + description: 'UUID of an intern in the workspace selected by the API key.' + example: '7c9e6679-7425-40de-944b-e07fc1f90ae7' + format: 'uuid' + type: 'string' + - description: 'Page size, 1 to 100. Defaults to 100.' + in: 'query' + name: 'limit' + required: false + schema: + default: 100 + description: 'Page size, 1 to 100. Defaults to 100.' + example: 50 + maximum: 100 + minimum: 1 + type: 'integer' + - description: 'Number of secrets to skip, 0 to 10000. Defaults to 0.' + in: 'query' + name: 'offset' + required: false + schema: + default: 0 + description: 'Number of secrets to skip, 0 to 10000. Defaults to 0.' + example: 0 + maximum: 10000 + minimum: 0 + type: 'integer' + nullable: false + responses: + '200': + content: + application/json: + example: + data: + - created_at: '2026-09-15T17:44:00.000Z' + fingerprint: 'sha256:9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08' + hosts: + - 'api.github.com' + name: 'github_token' + scope: 'intern' + - created_at: '2026-09-15T17:44:00.000Z' + fingerprint: 'sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb' + hosts: + - 'api.linear.app' + name: 'linear_api_key' + scope: 'workspace' + - created_at: '2026-08-01T09:30:00.000Z' + fingerprint: null + hosts: null + name: 'legacy_token' + scope: 'workspace' + has_more: false + schema: + $ref: '#/components/schemas/VaultEffectiveSecretListResponse' + description: 'One page of the secrets the intern receives.' + '400': + content: + application/json: + examples: + invalid-vault-request: + summary: 'Invalid vault request' + value: + error: + code: 400 + message: 'Invalid vault request' + schema: + $ref: '#/components/schemas/BadRequestResponse' + description: 'Bad Request - The secret name, path, query or JSON body failed validation. The vault returns 400 for a malformed request as well.' + '401': + content: + application/json: + examples: + invalid-or-missing-api-key: + summary: 'Invalid or missing API key' + value: + error: + code: 401 + message: 'Invalid or missing API key' + schema: + $ref: '#/components/schemas/UnauthorizedResponse' + description: 'Unauthorized - Missing or unknown API key. Provisioning keys cannot call vault routes.' + '403': + content: + application/json: + examples: + regional-hostname: + summary: 'Regional hostname' + value: + error: + code: 403 + message: 'The Intern API does not support regional data residency yet. Please use the global endpoint at openrouter.ai.' + workspace-scope-unavailable: + summary: 'Workspace scope unavailable' + value: + error: + code: 403 + message: 'Vault scope is unavailable' + schema: + $ref: '#/components/schemas/ForbiddenResponse' + description: 'Forbidden - The key has no usable workspace scope, or the request arrived on a regional hostname.' + '404': + content: + application/json: + examples: + not-found: + summary: 'Not found' + value: + error: + code: 404 + message: 'Not found' + schema: + $ref: '#/components/schemas/NotFoundResponse' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' + '408': + content: + application/json: + examples: + body-timed-out: + summary: 'Body timed out' + value: + error: + code: 408 + message: 'Request body timed out' + route-deadline: + summary: 'Route deadline' + value: + error: + code: 408 + message: 'Vault request timed out' + schema: + $ref: '#/components/schemas/RequestTimeoutResponse' + description: 'Request Timeout - The route deadline passed before the request completed, or the request body stopped arriving.' + '429': + content: + application/json: + examples: + rate-limited: + summary: 'Rate limited' + value: + error: + code: 429 + message: 'Too many vault requests' + schema: + $ref: '#/components/schemas/TooManyRequestsResponse' + description: 'Too Many Requests - The vault rate limit was reached.' + '500': + content: + application/json: + examples: + internal-error: + summary: 'Internal error' + value: + error: + code: 500 + message: 'Internal Server Error' + schema: + $ref: '#/components/schemas/InternalServerResponse' + description: 'Internal Server Error - Scope lookup failed.' + '502': + content: + application/json: + examples: + invalid-vault-response: + summary: 'Invalid vault response' + value: + error: + code: 502 + message: 'Invalid vault response' + vault-request-failed: + summary: 'Vault request failed' + value: + error: + code: 502 + message: 'Vault request failed' + schema: + $ref: '#/components/schemas/BadGatewayResponse' + description: 'Bad Gateway - The vault could not be reached or returned an unexpected response.' + '503': + content: + application/json: + examples: + vault-unavailable: + summary: 'Vault unavailable' + value: + error: + code: 503 + message: 'Vault service is unavailable' + writes-disabled: + summary: 'Writes disabled' + value: + error: + code: 503 + message: 'Vault writes are not enabled' + schema: + $ref: '#/components/schemas/ServiceUnavailableResponse' + description: 'Service Unavailable - Vault writes are disabled for the caller, or the vault is not configured.' + '504': + content: + application/json: + examples: + vault-timed-out: + summary: 'Vault timed out' + value: + error: + code: 504 + message: 'Vault request timed out' + schema: + $ref: '#/components/schemas/GatewayTimeoutResponse' + description: 'Gateway Timeout - The vault did not answer in time.' + security: + - apiKey: [] + summary: 'List the secrets an intern receives' + tags: + - 'Vault' + parameters: + - $ref: "#/components/parameters/AppIdentifier" + - $ref: "#/components/parameters/AppDisplayName" + - $ref: "#/components/parameters/AppCategories" /vault/interns/{internId}/secrets: get: - description: 'Lists secret metadata stored for one intern. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Lists secret metadata stored for one intern. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'listInternVaultSecrets' parameters: - description: 'UUID of an intern in the workspace selected by the API key.' @@ -48415,7 +48726,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: @@ -48523,7 +48834,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /vault/interns/{internId}/secrets/{name}: delete: - description: 'Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'deleteInternVaultSecret' parameters: - description: 'UUID of an intern in the workspace selected by the API key.' @@ -48606,7 +48917,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: @@ -48709,7 +49020,7 @@ paths: tags: - 'Vault' put: - description: 'Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'storeInternVaultSecret' parameters: - description: 'UUID of an intern in the workspace selected by the API key.' @@ -48813,7 +49124,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: @@ -48947,7 +49258,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /vault/interns/{internId}/secrets/copy: post: - description: 'Copies the named workspace secrets into one intern''s scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Copies the named workspace secrets into one intern''s scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'copyVaultSecretsToIntern' parameters: - description: 'UUID of an intern in the workspace selected by the API key.' @@ -49039,7 +49350,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: @@ -49173,7 +49484,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /vault/secrets: get: - description: 'Lists secret metadata for the workspace of the authenticated API key. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Lists secret metadata for the workspace of the authenticated API key. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'listVaultSecrets' parameters: - description: 'Page size, 1 to 100. Defaults to 100.' @@ -49275,7 +49586,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: @@ -49383,7 +49694,7 @@ paths: - $ref: "#/components/parameters/AppCategories" /vault/secrets/{name}: delete: - description: 'Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'deleteVaultSecret' parameters: - description: 'Secret name. Lowercase letters, digits and single underscores, starting with a letter and not ending with an underscore, 1 to 255 characters.' @@ -49457,7 +49768,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: @@ -49560,7 +49871,7 @@ paths: tags: - 'Vault' put: - description: 'Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' + description: 'Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key''s active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern''s own API key is confined to that intern: it can always read the intern''s secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required.' operationId: 'storeVaultSecret' parameters: - description: 'Secret name. Lowercase letters, digits and single underscores, starting with a letter and not ending with an underscore, 1 to 255 characters.' @@ -49655,7 +49966,7 @@ paths: message: 'Not found' schema: $ref: '#/components/schemas/NotFoundResponse' - description: 'Not Found - The intern is not in the selected workspace, the secret does not exist in the selected scope, or the caller is outside the intern programme.' + description: 'Not Found - The intern is not in the selected workspace or is not visible to the key (a member key without an admin role sees only interns its member created or interns in workspaces they administer), the secret does not exist in the selected scope, or the caller is outside the intern programme.' '408': content: application/json: diff --git a/.speakeasy/workflow.lock b/.speakeasy/workflow.lock index 55738b9b..5b103763 100644 --- a/.speakeasy/workflow.lock +++ b/.speakeasy/workflow.lock @@ -2,8 +2,8 @@ speakeasyVersion: 1.787.0 sources: OpenRouter API: sourceNamespace: open-router-chat-completions-api - sourceRevisionDigest: sha256:77833092b90f7e68c3d4892bd2f092d7bfee0703b8d027f05e8247f34b063ded - sourceBlobDigest: sha256:1bb6c8de10cfe9440ea0a95a3ae644ccad440c7851e9225e22087764493f1f05 + sourceRevisionDigest: sha256:7a83f0762c40aac3bb8e78a9c590061c91b3be862db4d3d9cad87f45580c5fa2 + sourceBlobDigest: sha256:9d55afd08572430be4aef479952e830a3c49344748fbd32cf8b8f62e45f34243 tags: - latest - 1.0.0 @@ -11,10 +11,10 @@ targets: open-router: source: OpenRouter API sourceNamespace: open-router-chat-completions-api - sourceRevisionDigest: sha256:77833092b90f7e68c3d4892bd2f092d7bfee0703b8d027f05e8247f34b063ded - sourceBlobDigest: sha256:1bb6c8de10cfe9440ea0a95a3ae644ccad440c7851e9225e22087764493f1f05 + sourceRevisionDigest: sha256:7a83f0762c40aac3bb8e78a9c590061c91b3be862db4d3d9cad87f45580c5fa2 + sourceBlobDigest: sha256:9d55afd08572430be4aef479952e830a3c49344748fbd32cf8b8f62e45f34243 codeSamplesNamespace: open-router-python-code-samples - codeSamplesRevisionDigest: sha256:421137ec0ba899d41251c3a83c819b71b205a0fe355971bbe8b248add9e1152d + codeSamplesRevisionDigest: sha256:2ec8c3cee3d23279e25cb1e3c6f85569c68842fe4e80f2cd7ae43f09e3032041 workflow: workflowVersion: 1.0.0 speakeasyVersion: 1.787.0 diff --git a/RELEASES.md b/RELEASES.md index ec944953..03c1a147 100644 --- a/RELEASES.md +++ b/RELEASES.md @@ -2769,4 +2769,14 @@ Based on: ### Generated - [python v1.3.0] . ### Releases -- [PyPI v1.3.0] https://pypi.org/project/openrouter/1.3.0 - . \ No newline at end of file +- [PyPI v1.3.0] https://pypi.org/project/openrouter/1.3.0 - . + +## 2026-09-29 02:09:24 +### Changes +Based on: +- OpenAPI Doc +- Speakeasy CLI 1.787.0 (2.914.0) https://github.com/speakeasy-api/speakeasy +### Generated +- [python v1.3.1] . +### Releases +- [PyPI v1.3.1] https://pypi.org/project/openrouter/1.3.1 - . \ No newline at end of file diff --git a/docs/components/scope.mdx b/docs/components/scope.mdx deleted file mode 100644 index ca4b238c..00000000 --- a/docs/components/scope.mdx +++ /dev/null @@ -1,17 +0,0 @@ ---- -title: "Scope" ---- - -Optional; only `inference` is available. - -## Example Usage - -```python -from openrouter.components import Scope -value: Scope = "inference" -``` - - -## Values - -- `"inference"` diff --git a/docs/components/tokenexchangerequest.mdx b/docs/components/tokenexchangerequest.mdx index 84a147af..a086ed56 100644 --- a/docs/components/tokenexchangerequest.mdx +++ b/docs/components/tokenexchangerequest.mdx @@ -12,6 +12,6 @@ RFC 8693 token exchange request body (application/x-www-form-urlencoded). | `federation_policy_id` | *str* | :heavy_check_mark: | The federation policy to evaluate, from Settings → Workload identity. Binds the exchange to one organization. | 4b2f7d1e-8c3a-4e5f-9a6b-1c2d3e4f5a6b | | `grant_type` | [components.GrantType](../components/granttype.mdx) | :heavy_check_mark: | Must be `urn:ietf:params:oauth:grant-type:token-exchange`. | urn:ietf:params:oauth:grant-type:token-exchange | | `requested_token_type` | [Optional[components.RequestedTokenType]](../components/requestedtokentype.mdx) | :heavy_minus_sign: | Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`. | urn:ietf:params:oauth:token-type:access_token | -| `scope` | [Optional[components.Scope]](../components/scope.mdx) | :heavy_minus_sign: | Optional; only `inference` is available. | inference | +| `scope` | [Optional[components.TokenExchangeRequestScope]](../components/tokenexchangerequestscope.mdx) | :heavy_minus_sign: | Optional; only `inference` is available. | inference | | `subject_token` | *str* | :heavy_check_mark: | The JWT issued by your identity provider. | \ | | `subject_token_type` | [components.SubjectTokenType](../components/subjecttokentype.mdx) | :heavy_check_mark: | Must be `urn:ietf:params:oauth:token-type:jwt`. | urn:ietf:params:oauth:token-type:jwt | \ No newline at end of file diff --git a/docs/components/tokenexchangerequestscope.mdx b/docs/components/tokenexchangerequestscope.mdx new file mode 100644 index 00000000..32b57f58 --- /dev/null +++ b/docs/components/tokenexchangerequestscope.mdx @@ -0,0 +1,17 @@ +--- +title: "TokenExchangeRequestScope" +--- + +Optional; only `inference` is available. + +## Example Usage + +```python +from openrouter.components import TokenExchangeRequestScope +value: TokenExchangeRequestScope = "inference" +``` + + +## Values + +- `"inference"` diff --git a/docs/components/vaulteffectivesecret.mdx b/docs/components/vaulteffectivesecret.mdx new file mode 100644 index 00000000..54d681fc --- /dev/null +++ b/docs/components/vaulteffectivesecret.mdx @@ -0,0 +1,16 @@ +--- +title: "VaultEffectiveSecret" +--- + +Metadata for the one secret the intern's outbound requests receive under this name. The secret value is never returned. The intern receives it only on requests to a hostname in `hosts`, or on any request when `hosts` is `null`; a request to any other hostname receives no secret under this name, even when another vault holds one. `fingerprint` is comparable only within one vault. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `created_at` | [date](https://docs.python.org/3/library/datetime.html#date-objects) | :heavy_check_mark: | N/A | +| `fingerprint` | *Nullable[str]* | :heavy_check_mark: | N/A | +| `hosts` | List[*str*] | :heavy_check_mark: | N/A | +| `name` | *str* | :heavy_check_mark: | N/A | +| `scope` | [components.VaultEffectiveSecretScope](../components/vaulteffectivesecretscope.mdx) | :heavy_check_mark: | Where the delivered secret is stored: `intern` for the intern's own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault. | \ No newline at end of file diff --git a/docs/components/vaulteffectivesecretlistresponse.mdx b/docs/components/vaulteffectivesecretlistresponse.mdx new file mode 100644 index 00000000..84fe50a0 --- /dev/null +++ b/docs/components/vaulteffectivesecretlistresponse.mdx @@ -0,0 +1,13 @@ +--- +title: "VaultEffectiveSecretListResponse" +--- + +One page of the secrets an intern receives, one entry per name. + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | +| `data` | List[[components.VaultEffectiveSecret](../components/vaulteffectivesecret.mdx)] | :heavy_check_mark: | N/A | +| `has_more` | *bool* | :heavy_check_mark: | True when more secrets exist beyond this page. Request the next page with `offset` increased by the number of returned entries. | \ No newline at end of file diff --git a/docs/components/vaulteffectivesecretscope.mdx b/docs/components/vaulteffectivesecretscope.mdx new file mode 100644 index 00000000..49bbc389 --- /dev/null +++ b/docs/components/vaulteffectivesecretscope.mdx @@ -0,0 +1,23 @@ +--- +title: "VaultEffectiveSecretScope" +--- + +Where the delivered secret is stored: `intern` for the intern's own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault. + +## Example Usage + +```python +from openrouter.components import VaultEffectiveSecretScope + +# Open enum: unrecognized values are captured as UnrecognizedStr +value: VaultEffectiveSecretScope = "intern" +``` + + +## Values + +This is an open enum. Unrecognized values will not fail type checks. + +- `"intern"` +- `"attached"` +- `"workspace"` diff --git a/docs/operations/listinterneffectivevaultsecretsglobals.mdx b/docs/operations/listinterneffectivevaultsecretsglobals.mdx new file mode 100644 index 00000000..bd5c8c46 --- /dev/null +++ b/docs/operations/listinterneffectivevaultsecretsglobals.mdx @@ -0,0 +1,11 @@ +--- +title: "ListInternEffectiveVaultSecretsGlobals" +--- + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | +| `http_referer` | *Optional[str]* | :heavy_minus_sign: | The app identifier should be your app's URL and is used as the primary identifier for rankings.
This is used to track API usage per application.
| +| `x_open_router_title` | *Optional[str]* | :heavy_minus_sign: | The app display name allows you to customize how your app appears in OpenRouter's dashboard.
| +| `x_open_router_categories` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of app categories (e.g. "cli-agent,cloud-agent"). Used for marketplace rankings.
| \ No newline at end of file diff --git a/docs/operations/listinterneffectivevaultsecretsrequest.mdx b/docs/operations/listinterneffectivevaultsecretsrequest.mdx new file mode 100644 index 00000000..ca1e31d1 --- /dev/null +++ b/docs/operations/listinterneffectivevaultsecretsrequest.mdx @@ -0,0 +1,14 @@ +--- +title: "ListInternEffectiveVaultSecretsRequest" +--- + +## Fields + +| Field | Type | Required | Description | Example | +| ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | +| `http_referer` | *Optional[str]* | :heavy_minus_sign: | The app identifier should be your app's URL and is used as the primary identifier for rankings.
This is used to track API usage per application.
| | +| `x_open_router_title` | *Optional[str]* | :heavy_minus_sign: | The app display name allows you to customize how your app appears in OpenRouter's dashboard.
| | +| `x_open_router_categories` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of app categories (e.g. "cli-agent,cloud-agent"). Used for marketplace rankings.
| | +| `intern_id` | *str* | :heavy_check_mark: | UUID of an intern in the workspace selected by the API key. | 7c9e6679-7425-40de-944b-e07fc1f90ae7 | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Page size, 1 to 100. Defaults to 100. | 50 | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Number of secrets to skip, 0 to 10000. Defaults to 0. | 0 | \ No newline at end of file diff --git a/docs/sdks/interns/README.mdx b/docs/sdks/interns/README.mdx index 9b2e94a1..93cafb95 100644 --- a/docs/sdks/interns/README.mdx +++ b/docs/sdks/interns/README.mdx @@ -23,7 +23,7 @@ Create, inspect, update, provision, suspend and delete OpenRouter interns throug ## list_interns -Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -73,7 +73,7 @@ with OpenRouter( ## create_intern -Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -126,7 +126,7 @@ with OpenRouter( ## delete_intern -Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{"acknowledge_workspace_loss": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{"acknowledge_workspace_loss": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -174,7 +174,7 @@ with OpenRouter( ## get_intern -Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -221,7 +221,7 @@ with OpenRouter( ## update_intern -Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -272,7 +272,7 @@ with OpenRouter( ## get_intern_daemon -Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -319,7 +319,7 @@ with OpenRouter( ## ~~get_intern_daemon_access~~ -Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. > :warning: **DEPRECATED**: This will be removed in a future release, please migrate away from it as soon as possible. @@ -368,7 +368,7 @@ with OpenRouter( ## provision_intern -Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -415,7 +415,7 @@ with OpenRouter( ## suspend_intern -Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage diff --git a/docs/sdks/oauth/README.mdx b/docs/sdks/oauth/README.mdx index 5e90344f..ac1d96c8 100644 --- a/docs/sdks/oauth/README.mdx +++ b/docs/sdks/oauth/README.mdx @@ -203,7 +203,7 @@ with OpenRouter( | `x_open_router_title` | *Optional[str]* | :heavy_minus_sign: | The app display name allows you to customize how your app appears in OpenRouter's dashboard.
| | | `x_open_router_categories` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of app categories (e.g. "cli-agent,cloud-agent"). Used for marketplace rankings.
| | | `requested_token_type` | [Optional[components.RequestedTokenType]](../../components/requestedtokentype.mdx) | :heavy_minus_sign: | Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`. | urn:ietf:params:oauth:token-type:access_token | -| `scope` | [Optional[components.Scope]](../../components/scope.mdx) | :heavy_minus_sign: | Optional; only `inference` is available. | inference | +| `scope` | [Optional[components.TokenExchangeRequestScope]](../../components/tokenexchangerequestscope.mdx) | :heavy_minus_sign: | Optional; only `inference` is available. | inference | | `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.mdx) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | | ### Response diff --git a/docs/sdks/vault/README.mdx b/docs/sdks/vault/README.mdx index 224e03ab..8d9386c0 100644 --- a/docs/sdks/vault/README.mdx +++ b/docs/sdks/vault/README.mdx @@ -9,6 +9,7 @@ Store host-bound secrets for a workspace or for one intern. Scope is selected by ### Available Operations +* [list_intern_effective_vault_secrets](#list_intern_effective_vault_secrets) - List the secrets an intern receives * [list_intern_vault_secrets](#list_intern_vault_secrets) - List intern secrets * [delete_intern_vault_secret](#delete_intern_vault_secret) - Delete an intern secret * [store_intern_vault_secret](#store_intern_vault_secret) - Store an intern secret @@ -17,9 +18,66 @@ Store host-bound secrets for a workspace or for one intern. Scope is selected by * [delete_vault_secret](#delete_vault_secret) - Delete a workspace secret * [store_vault_secret](#store_vault_secret) - Store a workspace secret +## list_intern_effective_vault_secrets + +Lists, one entry per name, the secret the intern's outbound requests receive: its own secrets, secrets from an attached vault, and workspace secrets, including ones stored before workspace-scoped storage. Where several vaults hold a name, the entry is the one that wins, in the order intern, attached, workspace. The same resolution decides what outbound requests receive, so this list and the intern's requests agree. `scope` says which vault the entry comes from. Responses carry metadata only, never values. Results are ordered by name and paginated with `limit` and `offset`. Returns 404 when the intern's attached vault is no longer available, since the intern then receives no secrets. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + +### Example Usage + +```python +from openrouter import OpenRouter +import os + + +with OpenRouter( + http_referer="", + x_open_router_title="", + x_open_router_categories="", + api_key=os.getenv("OPENROUTER_API_KEY", ""), +) as open_router: + + res = open_router.vault.list_intern_effective_vault_secrets(intern_id="7c9e6679-7425-40de-944b-e07fc1f90ae7", limit=50, offset=0) + + # Handle response + print(res) + +``` + +### Parameters + +| Parameter | Type | Required | Description | Example | +| ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | +| `intern_id` | *str* | :heavy_check_mark: | UUID of an intern in the workspace selected by the API key. | 7c9e6679-7425-40de-944b-e07fc1f90ae7 | +| `http_referer` | *Optional[str]* | :heavy_minus_sign: | The app identifier should be your app's URL and is used as the primary identifier for rankings.
This is used to track API usage per application.
| | +| `x_open_router_title` | *Optional[str]* | :heavy_minus_sign: | The app display name allows you to customize how your app appears in OpenRouter's dashboard.
| | +| `x_open_router_categories` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of app categories (e.g. "cli-agent,cloud-agent"). Used for marketplace rankings.
| | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Page size, 1 to 100. Defaults to 100. | 50 | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Number of secrets to skip, 0 to 10000. Defaults to 0. | 0 | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.mdx) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | | + +### Response + +**[components.VaultEffectiveSecretListResponse](../../components/vaulteffectivesecretlistresponse.mdx)** + +### Errors + +| Error Type | Status Code | Content Type | +| -------------------------------------- | -------------------------------------- | -------------------------------------- | +| errors.BadRequestResponseError | 400 | application/json | +| errors.UnauthorizedResponseError | 401 | application/json | +| errors.ForbiddenResponseError | 403 | application/json | +| errors.NotFoundResponseError | 404 | application/json | +| errors.RequestTimeoutResponseError | 408 | application/json | +| errors.TooManyRequestsResponseError | 429 | application/json | +| errors.InternalServerResponseError | 500 | application/json | +| errors.BadGatewayResponseError | 502 | application/json | +| errors.ServiceUnavailableResponseError | 503 | application/json | +| errors.GatewayTimeoutResponseError | 504 | application/json | +| errors.OpenRouterDefaultError | 4XX, 5XX | \*/\* | + ## list_intern_vault_secrets -Lists secret metadata stored for one intern. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Lists secret metadata stored for one intern. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -76,7 +134,7 @@ with OpenRouter( ## delete_intern_vault_secret -Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -127,7 +185,7 @@ with OpenRouter( ## store_intern_vault_secret -Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage: body-timed-out @@ -519,7 +577,7 @@ with OpenRouter( ## copy_vault_secrets_to_intern -Copies the named workspace secrets into one intern's scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Copies the named workspace secrets into one intern's scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage: body-timed-out @@ -909,7 +967,7 @@ with OpenRouter( ## list_vault_secrets -Lists secret metadata for the workspace of the authenticated API key. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Lists secret metadata for the workspace of the authenticated API key. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -965,7 +1023,7 @@ with OpenRouter( ## delete_vault_secret -Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage @@ -1015,7 +1073,7 @@ with OpenRouter( ## store_vault_secret -Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. +Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. ### Example Usage: body-timed-out diff --git a/pyproject.toml b/pyproject.toml index 9a4c2d4a..2abc2e9e 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "openrouter" -version = "1.3.0" +version = "1.3.1" description = "Official Python Client SDK for OpenRouter." authors = [{ name = "OpenRouter" },] readme = "README-PYPI.md" diff --git a/src/openrouter/_version.py b/src/openrouter/_version.py index c76512db..ebd042a8 100644 --- a/src/openrouter/_version.py +++ b/src/openrouter/_version.py @@ -3,10 +3,10 @@ import importlib.metadata __title__: str = "openrouter" -__version__: str = "1.3.0" +__version__: str = "1.3.1" __openapi_doc_version__: str = "1.0.0" __gen_version__: str = "2.914.0" -__user_agent__: str = "speakeasy-sdk/python 1.3.0 2.914.0 1.0.0 openrouter" +__user_agent__: str = "speakeasy-sdk/python 1.3.1 2.914.0 1.0.0 openrouter" try: if __package__ is not None: diff --git a/src/openrouter/components/__init__.py b/src/openrouter/components/__init__.py index 0ee45472..5c3c0093 100644 --- a/src/openrouter/components/__init__.py +++ b/src/openrouter/components/__init__.py @@ -3809,9 +3809,9 @@ from .tokenexchangerequest import ( GrantType, RequestedTokenType, - Scope, SubjectTokenType, TokenExchangeRequest, + TokenExchangeRequestScope, TokenExchangeRequestTypedDict, ) from .tokenexchangeresponse import ( @@ -3966,6 +3966,15 @@ ValidatePrivateEndpointRequest, ValidatePrivateEndpointRequestTypedDict, ) + from .vaulteffectivesecret import ( + VaultEffectiveSecret, + VaultEffectiveSecretScope, + VaultEffectiveSecretTypedDict, + ) + from .vaulteffectivesecretlistresponse import ( + VaultEffectiveSecretListResponse, + VaultEffectiveSecretListResponseTypedDict, + ) from .vaultsecret import VaultSecret, VaultSecretTypedDict from .vaultsecretcopyrequest import ( VaultSecretCopyRequest, @@ -6594,7 +6603,6 @@ "ScimSyncJob", "ScimSyncJobStatus", "ScimSyncJobTypedDict", - "Scope", "SearchContextSizeEnum", "SearchModelsServerToolConfig", "SearchModelsServerToolConfigTypedDict", @@ -6777,6 +6785,7 @@ "ThinkingTypeDisabled", "ThinkingTypedDict", "TokenExchangeRequest", + "TokenExchangeRequestScope", "TokenExchangeRequestTypedDict", "TokenExchangeResponse", "TokenExchangeResponseTypedDict", @@ -6996,6 +7005,11 @@ "ValidatePrivateEndpointRequestTypedDict", "Variables", "VariablesTypedDict", + "VaultEffectiveSecret", + "VaultEffectiveSecretListResponse", + "VaultEffectiveSecretListResponseTypedDict", + "VaultEffectiveSecretScope", + "VaultEffectiveSecretTypedDict", "VaultSecret", "VaultSecretCopyRequest", "VaultSecretCopyRequestTypedDict", @@ -9876,9 +9890,9 @@ "Verbosity": ".textextendedconfig", "GrantType": ".tokenexchangerequest", "RequestedTokenType": ".tokenexchangerequest", - "Scope": ".tokenexchangerequest", "SubjectTokenType": ".tokenexchangerequest", "TokenExchangeRequest": ".tokenexchangerequest", + "TokenExchangeRequestScope": ".tokenexchangerequest", "TokenExchangeRequestTypedDict": ".tokenexchangerequest", "IssuedTokenType": ".tokenexchangeresponse", "TokenExchangeResponse": ".tokenexchangeresponse", @@ -9978,6 +9992,11 @@ "URLCitationTypedDict": ".urlcitation", "ValidatePrivateEndpointRequest": ".validateprivateendpointrequest", "ValidatePrivateEndpointRequestTypedDict": ".validateprivateendpointrequest", + "VaultEffectiveSecret": ".vaulteffectivesecret", + "VaultEffectiveSecretScope": ".vaulteffectivesecret", + "VaultEffectiveSecretTypedDict": ".vaulteffectivesecret", + "VaultEffectiveSecretListResponse": ".vaulteffectivesecretlistresponse", + "VaultEffectiveSecretListResponseTypedDict": ".vaulteffectivesecretlistresponse", "VaultSecret": ".vaultsecret", "VaultSecretTypedDict": ".vaultsecret", "VaultSecretCopyRequest": ".vaultsecretcopyrequest", diff --git a/src/openrouter/components/tokenexchangerequest.py b/src/openrouter/components/tokenexchangerequest.py index a29bf176..10c0f8aa 100644 --- a/src/openrouter/components/tokenexchangerequest.py +++ b/src/openrouter/components/tokenexchangerequest.py @@ -16,7 +16,7 @@ r"""Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`.""" -Scope = Literal["inference",] +TokenExchangeRequestScope = Literal["inference",] r"""Optional; only `inference` is available.""" @@ -37,7 +37,7 @@ class TokenExchangeRequestTypedDict(TypedDict): r"""Must be `urn:ietf:params:oauth:token-type:jwt`.""" requested_token_type: NotRequired[RequestedTokenType] r"""Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`.""" - scope: NotRequired[Scope] + scope: NotRequired[TokenExchangeRequestScope] r"""Optional; only `inference` is available.""" @@ -61,7 +61,9 @@ class TokenExchangeRequest(BaseModel): ] = None r"""Optional; when present must be `urn:ietf:params:oauth:token-type:access_token`.""" - scope: Annotated[Optional[Scope], FieldMetadata(form=True)] = None + scope: Annotated[Optional[TokenExchangeRequestScope], FieldMetadata(form=True)] = ( + None + ) r"""Optional; only `inference` is available.""" @model_serializer(mode="wrap") diff --git a/src/openrouter/components/vaulteffectivesecret.py b/src/openrouter/components/vaulteffectivesecret.py new file mode 100644 index 00000000..370c71dc --- /dev/null +++ b/src/openrouter/components/vaulteffectivesecret.py @@ -0,0 +1,59 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from datetime import datetime +from openrouter.types import BaseModel, Nullable, UNSET_SENTINEL, UnrecognizedStr +from pydantic import model_serializer +from typing import List, Literal, Union +from typing_extensions import TypedDict + + +VaultEffectiveSecretScope = Union[ + Literal[ + "intern", + "attached", + "workspace", + ], + UnrecognizedStr, +] +r"""Where the delivered secret is stored: `intern` for the intern's own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault.""" + + +class VaultEffectiveSecretTypedDict(TypedDict): + r"""Metadata for the one secret the intern's outbound requests receive under this name. The secret value is never returned. The intern receives it only on requests to a hostname in `hosts`, or on any request when `hosts` is `null`; a request to any other hostname receives no secret under this name, even when another vault holds one. `fingerprint` is comparable only within one vault.""" + + created_at: datetime + fingerprint: Nullable[str] + hosts: Nullable[List[str]] + name: str + scope: VaultEffectiveSecretScope + r"""Where the delivered secret is stored: `intern` for the intern's own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault.""" + + +class VaultEffectiveSecret(BaseModel): + r"""Metadata for the one secret the intern's outbound requests receive under this name. The secret value is never returned. The intern receives it only on requests to a hostname in `hosts`, or on any request when `hosts` is `null`; a request to any other hostname receives no secret under this name, even when another vault holds one. `fingerprint` is comparable only within one vault.""" + + created_at: datetime + + fingerprint: Nullable[str] + + hosts: Nullable[List[str]] + + name: str + + scope: VaultEffectiveSecretScope + r"""Where the delivered secret is stored: `intern` for the intern's own vault, `attached` for a vault attached to the intern, `workspace` for the workspace vault.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + m[k] = val + + return m diff --git a/src/openrouter/components/vaulteffectivesecretlistresponse.py b/src/openrouter/components/vaulteffectivesecretlistresponse.py new file mode 100644 index 00000000..1624be98 --- /dev/null +++ b/src/openrouter/components/vaulteffectivesecretlistresponse.py @@ -0,0 +1,24 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .vaulteffectivesecret import VaultEffectiveSecret, VaultEffectiveSecretTypedDict +from openrouter.types import BaseModel +from typing import List +from typing_extensions import TypedDict + + +class VaultEffectiveSecretListResponseTypedDict(TypedDict): + r"""One page of the secrets an intern receives, one entry per name.""" + + data: List[VaultEffectiveSecretTypedDict] + has_more: bool + r"""True when more secrets exist beyond this page. Request the next page with `offset` increased by the number of returned entries.""" + + +class VaultEffectiveSecretListResponse(BaseModel): + r"""One page of the secrets an intern receives, one entry per name.""" + + data: List[VaultEffectiveSecret] + + has_more: bool + r"""True when more secrets exist beyond this page. Request the next page with `offset` increased by the number of returned entries.""" diff --git a/src/openrouter/interns.py b/src/openrouter/interns.py index dfcd3255..186fde86 100644 --- a/src/openrouter/interns.py +++ b/src/openrouter/interns.py @@ -36,7 +36,7 @@ def list_interns( ) -> components.InternListResponse: r"""List interns - Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -173,7 +173,7 @@ async def list_interns_async( ) -> components.InternListResponse: r"""List interns - Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Lists interns visible to the authenticated key, newest first. Filter by workspace and one or more lifecycle statuses. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -313,7 +313,7 @@ def create_intern( ) -> components.Intern: r"""Create an intern - Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -470,7 +470,7 @@ async def create_intern_async( ) -> components.Intern: r"""Create an intern - Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Creates an intern in an explicit workspace. The operation also creates its private vault. It can start provisioning immediately or wait for a later provision call. A retry with the same idempotency key and body resumes unfinished work. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -622,7 +622,7 @@ def delete_intern( ) -> components.DeleteInternResponse: r"""Delete an intern - Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{\"acknowledge_workspace_loss\": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{\"acknowledge_workspace_loss\": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -764,7 +764,7 @@ async def delete_intern_async( ) -> components.DeleteInternResponse: r"""Delete an intern - Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{\"acknowledge_workspace_loss\": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Starts safe teardown of the intern, its runtime and its private vault. The body is optional. Send `{\"acknowledge_workspace_loss\": true}` to delete a `destroy_failed` intern whose `last_failure_message` names `workspace_archive_failed`, accepting that its workspace is not backed up. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -905,7 +905,7 @@ def get_intern( ) -> components.Intern: r"""Get an intern - Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1033,7 +1033,7 @@ async def get_intern_async( ) -> components.Intern: r"""Get an intern - Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Returns the public lifecycle state and settings for one visible intern. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1165,7 +1165,7 @@ def update_intern( ) -> components.Intern: r"""Update an intern - Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1316,7 +1316,7 @@ async def update_intern_async( ) -> components.Intern: r"""Update an intern - Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Changes the intern name, description, instructions or model. Omitted fields stay unchanged. The request body is capped at 1048576 bytes and a larger body is refused with 413. A non-empty body must declare `Content-Type: application/json` or it is refused with 415. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1463,7 +1463,7 @@ def get_intern_daemon( ) -> components.InternDaemonAccess: r"""Get an intern's daemon access - Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1591,7 +1591,7 @@ async def get_intern_daemon_async( ) -> components.InternDaemonAccess: r"""Get an intern's daemon access - Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Returns the origin and daemon token that attach `ori tui --host` to one visible, running intern. The token is a credential: the response is sent with `Cache-Control: no-store`, and each reveal is logged by caller and intern. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1722,7 +1722,7 @@ def get_intern_daemon_access( ) -> components.InternDaemonAccess: r"""Get an intern's daemon access (deprecated alias) - Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1853,7 +1853,7 @@ async def get_intern_daemon_access_async( ) -> components.InternDaemonAccess: r"""Get an intern's daemon access (deprecated alias) - Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Deprecated alias of `GET /interns/{internId}/daemon` with the same request, response, and errors. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1981,7 +1981,7 @@ def provision_intern( ) -> components.ProvisionInternResponse: r"""Provision an intern - Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -2111,7 +2111,7 @@ async def provision_intern_async( ) -> components.ProvisionInternResponse: r"""Provision an intern - Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Starts the first boot, or resumes an intern after suspension. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -2241,7 +2241,7 @@ def suspend_intern( ) -> components.SuspendInternResponse: r"""Suspend an intern - Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -2371,7 +2371,7 @@ async def suspend_intern_async( ) -> components.SuspendInternResponse: r"""Suspend an intern - Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Stops the intern runtime while keeping its disk and configuration for a later provision call. This operation takes no request body. A body carrying any field is refused with 400 rather than ignored. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. diff --git a/src/openrouter/oauth.py b/src/openrouter/oauth.py index 67a81101..6f3d587f 100644 --- a/src/openrouter/oauth.py +++ b/src/openrouter/oauth.py @@ -892,7 +892,7 @@ def create_oauth_token( x_open_router_title: Optional[str] = None, x_open_router_categories: Optional[str] = None, requested_token_type: Optional[components.RequestedTokenType] = None, - scope: Optional[components.Scope] = None, + scope: Optional[components.TokenExchangeRequestScope] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, @@ -1039,7 +1039,7 @@ async def create_oauth_token_async( x_open_router_title: Optional[str] = None, x_open_router_categories: Optional[str] = None, requested_token_type: Optional[components.RequestedTokenType] = None, - scope: Optional[components.Scope] = None, + scope: Optional[components.TokenExchangeRequestScope] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, diff --git a/src/openrouter/operations/__init__.py b/src/openrouter/operations/__init__.py index 7f5a4f0e..021994be 100644 --- a/src/openrouter/operations/__init__.py +++ b/src/openrouter/operations/__init__.py @@ -763,6 +763,12 @@ ListImageModelsRequest, ListImageModelsRequestTypedDict, ) + from .listinterneffectivevaultsecrets import ( + ListInternEffectiveVaultSecretsGlobals, + ListInternEffectiveVaultSecretsGlobalsTypedDict, + ListInternEffectiveVaultSecretsRequest, + ListInternEffectiveVaultSecretsRequestTypedDict, + ) from .listinterns import ( ListInternsGlobals, ListInternsGlobalsTypedDict, @@ -1633,6 +1639,10 @@ "ListImageModelsGlobalsTypedDict", "ListImageModelsRequest", "ListImageModelsRequestTypedDict", + "ListInternEffectiveVaultSecretsGlobals", + "ListInternEffectiveVaultSecretsGlobalsTypedDict", + "ListInternEffectiveVaultSecretsRequest", + "ListInternEffectiveVaultSecretsRequestTypedDict", "ListInternVaultSecretsGlobals", "ListInternVaultSecretsGlobalsTypedDict", "ListInternVaultSecretsRequest", @@ -2466,6 +2476,10 @@ "ListImageModelsGlobalsTypedDict": ".listimagemodels", "ListImageModelsRequest": ".listimagemodels", "ListImageModelsRequestTypedDict": ".listimagemodels", + "ListInternEffectiveVaultSecretsGlobals": ".listinterneffectivevaultsecrets", + "ListInternEffectiveVaultSecretsGlobalsTypedDict": ".listinterneffectivevaultsecrets", + "ListInternEffectiveVaultSecretsRequest": ".listinterneffectivevaultsecrets", + "ListInternEffectiveVaultSecretsRequestTypedDict": ".listinterneffectivevaultsecrets", "ListInternsGlobals": ".listinterns", "ListInternsGlobalsTypedDict": ".listinterns", "ListInternsRequest": ".listinterns", diff --git a/src/openrouter/operations/listinterneffectivevaultsecrets.py b/src/openrouter/operations/listinterneffectivevaultsecrets.py new file mode 100644 index 00000000..aa75b78b --- /dev/null +++ b/src/openrouter/operations/listinterneffectivevaultsecrets.py @@ -0,0 +1,173 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from openrouter.types import BaseModel, UNSET_SENTINEL +from openrouter.utils import ( + FieldMetadata, + HeaderMetadata, + PathParamMetadata, + QueryParamMetadata, +) +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class ListInternEffectiveVaultSecretsGlobalsTypedDict(TypedDict): + http_referer: NotRequired[str] + r"""The app identifier should be your app's URL and is used as the primary identifier for rankings. + This is used to track API usage per application. + + """ + x_open_router_title: NotRequired[str] + r"""The app display name allows you to customize how your app appears in OpenRouter's dashboard. + + """ + x_open_router_categories: NotRequired[str] + r"""Comma-separated list of app categories (e.g. \"cli-agent,cloud-agent\"). Used for marketplace rankings. + + """ + + +class ListInternEffectiveVaultSecretsGlobals(BaseModel): + http_referer: Annotated[ + Optional[str], + pydantic.Field(alias="HTTP-Referer"), + FieldMetadata(header=HeaderMetadata(style="simple", explode=False)), + ] = None + r"""The app identifier should be your app's URL and is used as the primary identifier for rankings. + This is used to track API usage per application. + + """ + + x_open_router_title: Annotated[ + Optional[str], + pydantic.Field(alias="X-OpenRouter-Title"), + FieldMetadata(header=HeaderMetadata(style="simple", explode=False)), + ] = None + r"""The app display name allows you to customize how your app appears in OpenRouter's dashboard. + + """ + + x_open_router_categories: Annotated[ + Optional[str], + pydantic.Field(alias="X-OpenRouter-Categories"), + FieldMetadata(header=HeaderMetadata(style="simple", explode=False)), + ] = None + r"""Comma-separated list of app categories (e.g. \"cli-agent,cloud-agent\"). Used for marketplace rankings. + + """ + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["HTTP-Referer", "X-OpenRouter-Title", "X-OpenRouter-Categories"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class ListInternEffectiveVaultSecretsRequestTypedDict(TypedDict): + intern_id: str + r"""UUID of an intern in the workspace selected by the API key.""" + http_referer: NotRequired[str] + r"""The app identifier should be your app's URL and is used as the primary identifier for rankings. + This is used to track API usage per application. + + """ + x_open_router_title: NotRequired[str] + r"""The app display name allows you to customize how your app appears in OpenRouter's dashboard. + + """ + x_open_router_categories: NotRequired[str] + r"""Comma-separated list of app categories (e.g. \"cli-agent,cloud-agent\"). Used for marketplace rankings. + + """ + limit: NotRequired[int] + r"""Page size, 1 to 100. Defaults to 100.""" + offset: NotRequired[int] + r"""Number of secrets to skip, 0 to 10000. Defaults to 0.""" + + +class ListInternEffectiveVaultSecretsRequest(BaseModel): + intern_id: Annotated[ + str, + pydantic.Field(alias="internId"), + FieldMetadata(path=PathParamMetadata(style="simple", explode=False)), + ] + r"""UUID of an intern in the workspace selected by the API key.""" + + http_referer: Annotated[ + Optional[str], + pydantic.Field(alias="HTTP-Referer"), + FieldMetadata(header=HeaderMetadata(style="simple", explode=False)), + ] = None + r"""The app identifier should be your app's URL and is used as the primary identifier for rankings. + This is used to track API usage per application. + + """ + + x_open_router_title: Annotated[ + Optional[str], + pydantic.Field(alias="X-OpenRouter-Title"), + FieldMetadata(header=HeaderMetadata(style="simple", explode=False)), + ] = None + r"""The app display name allows you to customize how your app appears in OpenRouter's dashboard. + + """ + + x_open_router_categories: Annotated[ + Optional[str], + pydantic.Field(alias="X-OpenRouter-Categories"), + FieldMetadata(header=HeaderMetadata(style="simple", explode=False)), + ] = None + r"""Comma-separated list of app categories (e.g. \"cli-agent,cloud-agent\"). Used for marketplace rankings. + + """ + + limit: Annotated[ + Optional[int], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = 100 + r"""Page size, 1 to 100. Defaults to 100.""" + + offset: Annotated[ + Optional[int], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = 0 + r"""Number of secrets to skip, 0 to 10000. Defaults to 0.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "HTTP-Referer", + "X-OpenRouter-Title", + "X-OpenRouter-Categories", + "limit", + "offset", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m diff --git a/src/openrouter/vault.py b/src/openrouter/vault.py index d73bcc0f..7619f073 100644 --- a/src/openrouter/vault.py +++ b/src/openrouter/vault.py @@ -12,6 +12,354 @@ class Vault(BaseSDK): r"""Store host-bound secrets for a workspace or for one intern. Scope is selected by the API key. Responses return metadata only, never secret values. See https://openrouter.ai/docs/guides/ori/vault.""" + def list_intern_effective_vault_secrets( + self, + *, + intern_id: str, + http_referer: Optional[str] = None, + x_open_router_title: Optional[str] = None, + x_open_router_categories: Optional[str] = None, + limit: Optional[int] = 100, + offset: Optional[int] = 0, + retries: OptionalNullable[utils.RetryConfig] = UNSET, + server_url: Optional[str] = None, + timeout_ms: Optional[int] = None, + http_headers: Optional[Mapping[str, str]] = None, + ) -> components.VaultEffectiveSecretListResponse: + r"""List the secrets an intern receives + + Lists, one entry per name, the secret the intern's outbound requests receive: its own secrets, secrets from an attached vault, and workspace secrets, including ones stored before workspace-scoped storage. Where several vaults hold a name, the entry is the one that wins, in the order intern, attached, workspace. The same resolution decides what outbound requests receive, so this list and the intern's requests agree. `scope` says which vault the entry comes from. Responses carry metadata only, never values. Results are ordered by name and paginated with `limit` and `offset`. Returns 404 when the intern's attached vault is no longer available, since the intern then receives no secrets. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + + If set, this operation will use `api_key` from the global security. + + :param intern_id: UUID of an intern in the workspace selected by the API key. + :param http_referer: The app identifier should be your app's URL and is used as the primary identifier for rankings. + This is used to track API usage per application. + + :param x_open_router_title: The app display name allows you to customize how your app appears in OpenRouter's dashboard. + + :param x_open_router_categories: Comma-separated list of app categories (e.g. \"cli-agent,cloud-agent\"). Used for marketplace rankings. + + :param limit: Page size, 1 to 100. Defaults to 100. + :param offset: Number of secrets to skip, 0 to 10000. Defaults to 0. + :param retries: Override the default retry configuration for this method + :param server_url: Override the default server URL for this method + :param timeout_ms: Override the default request timeout configuration for this method in milliseconds + :param http_headers: Additional headers to set or replace on requests. + """ + base_url = None + url_variables = None + if timeout_ms is None: + timeout_ms = self.sdk_configuration.timeout_ms + + if server_url is not None: + base_url = server_url + else: + base_url = self._get_url(base_url, url_variables) + + request = operations.ListInternEffectiveVaultSecretsRequest( + http_referer=http_referer, + x_open_router_title=x_open_router_title, + x_open_router_categories=x_open_router_categories, + intern_id=intern_id, + limit=limit, + offset=offset, + ) + + req = self._build_request( + method="GET", + path="/vault/interns/{internId}/effective-secrets", + base_url=base_url, + url_variables=url_variables, + request=request, + request_body_required=False, + request_has_path_params=True, + request_has_query_params=True, + user_agent_header="user-agent", + accept_header_value="application/json", + http_headers=http_headers, + _globals=operations.ListInternEffectiveVaultSecretsGlobals( + http_referer=self.sdk_configuration.globals.http_referer, + x_open_router_title=self.sdk_configuration.globals.x_open_router_title, + x_open_router_categories=self.sdk_configuration.globals.x_open_router_categories, + ), + security=self.sdk_configuration.security, + allow_empty_value=None, + allowed_fields=["api_key"], + timeout_ms=timeout_ms, + ) + + if retries == UNSET: + if self.sdk_configuration.retry_config is not UNSET: + retries = self.sdk_configuration.retry_config + else: + retries = utils.RetryConfig( + "backoff", utils.BackoffStrategy(500, 60000, 1.5, 3600000), True + ) + + retry_config = None + if isinstance(retries, utils.RetryConfig): + retry_config = (retries, ["5XX"]) + + http_res = self.do_request( + hook_ctx=HookContext( + config=self.sdk_configuration, + base_url=base_url or "", + operation_id="listInternEffectiveVaultSecrets", + oauth2_scopes=None, + security_source=get_security_from_env( + self.sdk_configuration.security, components.Security + ), + tags=["Vault"], + extensions=None, + ), + request=req, + is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), + retry_config=retry_config, + ) + + response_data: Any = None + if utils.match_response(http_res, "200", "application/json"): + return unmarshal_json_response( + components.VaultEffectiveSecretListResponse, http_res + ) + if utils.match_response(http_res, "400", "application/json"): + response_data = unmarshal_json_response( + errors.BadRequestResponseErrorData, http_res + ) + raise errors.BadRequestResponseError(response_data, http_res) + if utils.match_response(http_res, "401", "application/json"): + response_data = unmarshal_json_response( + errors.UnauthorizedResponseErrorData, http_res + ) + raise errors.UnauthorizedResponseError(response_data, http_res) + if utils.match_response(http_res, "403", "application/json"): + response_data = unmarshal_json_response( + errors.ForbiddenResponseErrorData, http_res + ) + raise errors.ForbiddenResponseError(response_data, http_res) + if utils.match_response(http_res, "404", "application/json"): + response_data = unmarshal_json_response( + errors.NotFoundResponseErrorData, http_res + ) + raise errors.NotFoundResponseError(response_data, http_res) + if utils.match_response(http_res, "408", "application/json"): + response_data = unmarshal_json_response( + errors.RequestTimeoutResponseErrorData, http_res + ) + raise errors.RequestTimeoutResponseError(response_data, http_res) + if utils.match_response(http_res, "429", "application/json"): + response_data = unmarshal_json_response( + errors.TooManyRequestsResponseErrorData, http_res + ) + raise errors.TooManyRequestsResponseError(response_data, http_res) + if utils.match_response(http_res, "500", "application/json"): + response_data = unmarshal_json_response( + errors.InternalServerResponseErrorData, http_res + ) + raise errors.InternalServerResponseError(response_data, http_res) + if utils.match_response(http_res, "502", "application/json"): + response_data = unmarshal_json_response( + errors.BadGatewayResponseErrorData, http_res + ) + raise errors.BadGatewayResponseError(response_data, http_res) + if utils.match_response(http_res, "503", "application/json"): + response_data = unmarshal_json_response( + errors.ServiceUnavailableResponseErrorData, http_res + ) + raise errors.ServiceUnavailableResponseError(response_data, http_res) + if utils.match_response(http_res, "504", "application/json"): + response_data = unmarshal_json_response( + errors.GatewayTimeoutResponseErrorData, http_res + ) + raise errors.GatewayTimeoutResponseError(response_data, http_res) + if utils.match_response(http_res, "4XX", "*"): + http_res_text = utils.stream_to_text(http_res) + raise errors.OpenRouterDefaultError( + "API error occurred", http_res, http_res_text + ) + if utils.match_response(http_res, "5XX", "*"): + http_res_text = utils.stream_to_text(http_res) + raise errors.OpenRouterDefaultError( + "API error occurred", http_res, http_res_text + ) + + raise errors.OpenRouterDefaultError("Unexpected response received", http_res) + + async def list_intern_effective_vault_secrets_async( + self, + *, + intern_id: str, + http_referer: Optional[str] = None, + x_open_router_title: Optional[str] = None, + x_open_router_categories: Optional[str] = None, + limit: Optional[int] = 100, + offset: Optional[int] = 0, + retries: OptionalNullable[utils.RetryConfig] = UNSET, + server_url: Optional[str] = None, + timeout_ms: Optional[int] = None, + http_headers: Optional[Mapping[str, str]] = None, + ) -> components.VaultEffectiveSecretListResponse: + r"""List the secrets an intern receives + + Lists, one entry per name, the secret the intern's outbound requests receive: its own secrets, secrets from an attached vault, and workspace secrets, including ones stored before workspace-scoped storage. Where several vaults hold a name, the entry is the one that wins, in the order intern, attached, workspace. The same resolution decides what outbound requests receive, so this list and the intern's requests agree. `scope` says which vault the entry comes from. Responses carry metadata only, never values. Results are ordered by name and paginated with `limit` and `offset`. Returns 404 when the intern's attached vault is no longer available, since the intern then receives no secrets. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + + If set, this operation will use `api_key` from the global security. + + :param intern_id: UUID of an intern in the workspace selected by the API key. + :param http_referer: The app identifier should be your app's URL and is used as the primary identifier for rankings. + This is used to track API usage per application. + + :param x_open_router_title: The app display name allows you to customize how your app appears in OpenRouter's dashboard. + + :param x_open_router_categories: Comma-separated list of app categories (e.g. \"cli-agent,cloud-agent\"). Used for marketplace rankings. + + :param limit: Page size, 1 to 100. Defaults to 100. + :param offset: Number of secrets to skip, 0 to 10000. Defaults to 0. + :param retries: Override the default retry configuration for this method + :param server_url: Override the default server URL for this method + :param timeout_ms: Override the default request timeout configuration for this method in milliseconds + :param http_headers: Additional headers to set or replace on requests. + """ + base_url = None + url_variables = None + if timeout_ms is None: + timeout_ms = self.sdk_configuration.timeout_ms + + if server_url is not None: + base_url = server_url + else: + base_url = self._get_url(base_url, url_variables) + + request = operations.ListInternEffectiveVaultSecretsRequest( + http_referer=http_referer, + x_open_router_title=x_open_router_title, + x_open_router_categories=x_open_router_categories, + intern_id=intern_id, + limit=limit, + offset=offset, + ) + + req = self._build_request_async( + method="GET", + path="/vault/interns/{internId}/effective-secrets", + base_url=base_url, + url_variables=url_variables, + request=request, + request_body_required=False, + request_has_path_params=True, + request_has_query_params=True, + user_agent_header="user-agent", + accept_header_value="application/json", + http_headers=http_headers, + _globals=operations.ListInternEffectiveVaultSecretsGlobals( + http_referer=self.sdk_configuration.globals.http_referer, + x_open_router_title=self.sdk_configuration.globals.x_open_router_title, + x_open_router_categories=self.sdk_configuration.globals.x_open_router_categories, + ), + security=self.sdk_configuration.security, + allow_empty_value=None, + allowed_fields=["api_key"], + timeout_ms=timeout_ms, + ) + + if retries == UNSET: + if self.sdk_configuration.retry_config is not UNSET: + retries = self.sdk_configuration.retry_config + else: + retries = utils.RetryConfig( + "backoff", utils.BackoffStrategy(500, 60000, 1.5, 3600000), True + ) + + retry_config = None + if isinstance(retries, utils.RetryConfig): + retry_config = (retries, ["5XX"]) + + http_res = await self.do_request_async( + hook_ctx=HookContext( + config=self.sdk_configuration, + base_url=base_url or "", + operation_id="listInternEffectiveVaultSecrets", + oauth2_scopes=None, + security_source=get_security_from_env( + self.sdk_configuration.security, components.Security + ), + tags=["Vault"], + extensions=None, + ), + request=req, + is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), + retry_config=retry_config, + ) + + response_data: Any = None + if utils.match_response(http_res, "200", "application/json"): + return unmarshal_json_response( + components.VaultEffectiveSecretListResponse, http_res + ) + if utils.match_response(http_res, "400", "application/json"): + response_data = unmarshal_json_response( + errors.BadRequestResponseErrorData, http_res + ) + raise errors.BadRequestResponseError(response_data, http_res) + if utils.match_response(http_res, "401", "application/json"): + response_data = unmarshal_json_response( + errors.UnauthorizedResponseErrorData, http_res + ) + raise errors.UnauthorizedResponseError(response_data, http_res) + if utils.match_response(http_res, "403", "application/json"): + response_data = unmarshal_json_response( + errors.ForbiddenResponseErrorData, http_res + ) + raise errors.ForbiddenResponseError(response_data, http_res) + if utils.match_response(http_res, "404", "application/json"): + response_data = unmarshal_json_response( + errors.NotFoundResponseErrorData, http_res + ) + raise errors.NotFoundResponseError(response_data, http_res) + if utils.match_response(http_res, "408", "application/json"): + response_data = unmarshal_json_response( + errors.RequestTimeoutResponseErrorData, http_res + ) + raise errors.RequestTimeoutResponseError(response_data, http_res) + if utils.match_response(http_res, "429", "application/json"): + response_data = unmarshal_json_response( + errors.TooManyRequestsResponseErrorData, http_res + ) + raise errors.TooManyRequestsResponseError(response_data, http_res) + if utils.match_response(http_res, "500", "application/json"): + response_data = unmarshal_json_response( + errors.InternalServerResponseErrorData, http_res + ) + raise errors.InternalServerResponseError(response_data, http_res) + if utils.match_response(http_res, "502", "application/json"): + response_data = unmarshal_json_response( + errors.BadGatewayResponseErrorData, http_res + ) + raise errors.BadGatewayResponseError(response_data, http_res) + if utils.match_response(http_res, "503", "application/json"): + response_data = unmarshal_json_response( + errors.ServiceUnavailableResponseErrorData, http_res + ) + raise errors.ServiceUnavailableResponseError(response_data, http_res) + if utils.match_response(http_res, "504", "application/json"): + response_data = unmarshal_json_response( + errors.GatewayTimeoutResponseErrorData, http_res + ) + raise errors.GatewayTimeoutResponseError(response_data, http_res) + if utils.match_response(http_res, "4XX", "*"): + http_res_text = await utils.stream_to_text_async(http_res) + raise errors.OpenRouterDefaultError( + "API error occurred", http_res, http_res_text + ) + if utils.match_response(http_res, "5XX", "*"): + http_res_text = await utils.stream_to_text_async(http_res) + raise errors.OpenRouterDefaultError( + "API error occurred", http_res, http_res_text + ) + + raise errors.OpenRouterDefaultError("Unexpected response received", http_res) + def list_intern_vault_secrets( self, *, @@ -28,7 +376,7 @@ def list_intern_vault_secrets( ) -> components.VaultSecretListResponse: r"""List intern secrets - Lists secret metadata stored for one intern. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Lists secret metadata stored for one intern. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -200,7 +548,7 @@ async def list_intern_vault_secrets_async( ) -> components.VaultSecretListResponse: r"""List intern secrets - Lists secret metadata stored for one intern. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Lists secret metadata stored for one intern. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -371,7 +719,7 @@ def delete_intern_vault_secret( ): r"""Delete an intern secret - Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -540,7 +888,7 @@ async def delete_intern_vault_secret_async( ): r"""Delete an intern secret - Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Deletes a secret stored for one intern. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -711,7 +1059,7 @@ def store_intern_vault_secret( ) -> components.VaultSecretResponse: r"""Store an intern secret - Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -905,7 +1253,7 @@ async def store_intern_vault_secret_async( ) -> components.VaultSecretResponse: r"""Store an intern secret - Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Creates or replaces a secret stored for one intern. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1097,7 +1445,7 @@ def copy_vault_secrets_to_intern( ) -> components.VaultSecretCopyResponse: r"""Copy workspace secrets to an intern - Copies the named workspace secrets into one intern's scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Copies the named workspace secrets into one intern's scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1285,7 +1633,7 @@ async def copy_vault_secrets_to_intern_async( ) -> components.VaultSecretCopyResponse: r"""Copy workspace secrets to an intern - Copies the named workspace secrets into one intern's scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Copies the named workspace secrets into one intern's scope, replacing any intern secret with the same name. Each copy keeps the source value and host bindings. Every name must exist in the workspace scope or the request fails with 404 and nothing is copied. A workspace secret whose `hosts` is `null` cannot be copied: the request fails with 409 and nothing is copied until that secret is stored again with hosts. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1473,7 +1821,7 @@ def list_vault_secrets( ) -> components.VaultSecretListResponse: r"""List workspace secrets - Lists secret metadata for the workspace of the authenticated API key. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Lists secret metadata for the workspace of the authenticated API key. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1642,7 +1990,7 @@ async def list_vault_secrets_async( ) -> components.VaultSecretListResponse: r"""List workspace secrets - Lists secret metadata for the workspace of the authenticated API key. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Lists secret metadata for the workspace of the authenticated API key. The list includes secrets stored from the dashboard or at provisioning before workspace-scoped storage; where both exist under one name, the one stored through this API is listed. Those older secrets cannot be deleted or copied through this API, and storing the same name through this API replaces them. Responses contain names, bound hosts, fingerprints and creation times, never secret values. Results are ordered by name and paginated with `limit` and `offset`. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1810,7 +2158,7 @@ def delete_vault_secret( ): r"""Delete a workspace secret - Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -1976,7 +2324,7 @@ async def delete_vault_secret_async( ): r"""Delete a workspace secret - Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Deletes a secret from the workspace of the authenticated API key. Returns 204 with no body on success and 404 when the secret does not exist in the selected scope. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -2144,7 +2492,7 @@ def store_vault_secret( ) -> components.VaultSecretResponse: r"""Store a workspace secret - Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. @@ -2330,7 +2678,7 @@ async def store_vault_secret_async( ) -> components.VaultSecretResponse: r"""Store a workspace secret - Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. + Creates or replaces a secret in the workspace of the authenticated API key. The value is encrypted at rest and released only to the exact hostnames in `hosts`. The response carries metadata only. Writes return 503 while vault writes are disabled for the caller. The scope is selected by the API key: workspace routes act on the key's active workspace and intern routes act on one intern inside that workspace. There is no default workspace and no fallback to another scope. Every vault route, including reads, requires access to the Intern API programme and returns 404 outside it. An intern's own API key is confined to that intern: it can always read the intern's secrets and effective secrets, writes to them follow the rules above, and every other intern and every workspace route answers 404. Requests on regional hostnames such as `eu.openrouter.ai` are refused. [API key](/docs/api-reference/authentication) required. If set, this operation will use `api_key` from the global security. diff --git a/uv.lock b/uv.lock index eeb07e36..bce5910e 100644 --- a/uv.lock +++ b/uv.lock @@ -213,7 +213,7 @@ wheels = [ [[package]] name = "openrouter" -version = "1.3.0" +version = "1.3.1" source = { editable = "." } dependencies = [ { name = "httpcore" },