Set a model key
Set the agency default (omit location_id) or one client's override. The key is checked with the provider first (422 key_rejected if it is refused), encrypted, and never returned again. Replacing a key clears its last_error. Agency key (ak_) only: mcp_ keys get 403 not_available_to_scoped_keys, so a provider key never passes through an AI tool.
curl -X PUT "https://mythic-analytics.gulp.workers.dev/client/v1/replay-vision/keys" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-d '{
"provider": "openrouter",
"api_key": "example_string",
"location_id": "example_string",
"default_model": "example_string",
"confirm_paid_tier": true
}'
import requests
import json
url = "https://mythic-analytics.gulp.workers.dev/client/v1/replay-vision/keys"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
data = {
"provider": "openrouter",
"api_key": "example_string",
"location_id": "example_string",
"default_model": "example_string",
"confirm_paid_tier": true
}
response = requests.put(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://mythic-analytics.gulp.workers.dev/client/v1/replay-vision/keys", {
method: "PUT",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
},
body: JSON.stringify({
"provider": "openrouter",
"api_key": "example_string",
"location_id": "example_string",
"default_model": "example_string",
"confirm_paid_tier": true
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"provider": "openrouter",
"api_key": "example_string",
"location_id": "example_string",
"default_model": "example_string",
"confirm_paid_tier": true
}`)
req, err := http.NewRequest("PUT", "https://mythic-analytics.gulp.workers.dev/client/v1/replay-vision/keys", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://mythic-analytics.gulp.workers.dev/client/v1/replay-vision/keys')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Put.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
request.body = '{
"provider": "openrouter",
"api_key": "example_string",
"location_id": "example_string",
"default_model": "example_string",
"confirm_paid_tier": true
}'
response = http.request(request)
puts response.body
{
"success": true,
"data": {
"id": "123e4567-e89b-12d3-a456-426614174000",
"scope": "agency",
"location_id": "example_string",
"provider": "openrouter",
"key_hint": "…a1b2",
"default_model": "example_string",
"verified_at": "2024-12-25T10:00:00Z",
"last_error": "example_string",
"last_error_at": "2024-12-25T10:00:00Z",
"updated_at": "2024-12-25T10:00:00Z"
}
}
{
"success": true,
"data": {
"id": "123e4567-e89b-12d3-a456-426614174000",
"scope": "agency",
"location_id": "example_string",
"provider": "openrouter",
"key_hint": "…a1b2",
"default_model": "example_string",
"verified_at": "2024-12-25T10:00:00Z",
"last_error": "example_string",
"last_error_at": "2024-12-25T10:00:00Z",
"updated_at": "2024-12-25T10:00:00Z"
}
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Unprocessable Entity",
"message": "The request was well-formed but contains semantic errors",
"code": 422,
"details": [
{
"field": "password",
"message": "Password must be at least 8 characters long"
}
]
}
/client/v1/replay-vision/keys
Target server for requests. Edit to use your own host.
Agency key (ak_) only; a location secret key (sk_) gets 403 agency_required. Agency-wide scoped keys (mcp_) need replay_vision:read or replay_vision:write.
ak_) only; a location secret key (sk_) gets 403 agency_required. Agency-wide scoped keys (mcp_) need replay_vision:read or replay_vision:write.The media type of the request body
The provider API key.
A client id for an override. Omit or null for the agency default.
Model used when a scanner sets none. Must be a model id of provider (400 otherwise). Default google/gemini-3.5-flash-lite (OpenRouter) or gemini-3.5-flash-lite (Gemini).
Required true for gemini: free-tier keys let Google use request content.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Agency key (ak_) only; a location secret key (sk_) gets 403 agency_required. Agency-wide scoped keys (mcp_) need replay_vision:read or replay_vision:write.
Body
openroutergeminiThe provider API key.
A client id for an override. Omit or null for the agency default.
Model used when a scanner sets none. Must be a model id of provider (400 otherwise). Default google/gemini-3.5-flash-lite (OpenRouter) or gemini-3.5-flash-lite (Gemini).
Required true for gemini: free-tier keys let Google use request content.